CVE-2025-58249: WordPress Qubely Plugin <= 1.8.14 - Sensitive Data Exposure Vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in Themeum Qubely allows Retrieve Embedded Sensitive Data. This issue affects Qubely: from n/a through 1.8.14.
Other sources
Insertion of Sensitive Information Into Sent Data vulnerability in Themeum Qubely qubely allows Retrieve Embedded Sensitive Data.This issue affects Qubely: from n/a through <= 1.8.14.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58249?
CVE-2025-58249 is considered a high severity vulnerability due to its potential for exposing sensitive information.
How do I fix CVE-2025-58249?
To fix CVE-2025-58249, update the Themeum Qubely plugin to version 1.8.15 or later.
What type of data is affected by CVE-2025-58249?
CVE-2025-58249 involves the retrieval of embedded sensitive data within transmitted content.
Who is affected by CVE-2025-58249?
Users of Themeum Qubely versions from n/a to 1.8.14 are affected by CVE-2025-58249.
What should I do if I can't update to fix CVE-2025-58249?
If you cannot update, consider disabling the Qubely plugin or implementing strict access controls to mitigate the risk associated with CVE-2025-58249.