CVE-2025-54735
8.8Imran Tauqeer · CubeWP Framework
The CubeWP Framework plugin for WordPress contains an Incorrect Privilege Assignment vulnerability that allows authenticated users to escalate their privileges within the application.
Executive summary
A critical privilege escalation vulnerability in the CubeWP Framework plugin for WordPress allows authenticated attackers to gain unauthorized administrative access.
Vulnerability
The vulnerability involves an Incorrect Privilege Assignment (CWE-266) within the framework, which can be triggered by an authenticated user with low-level privileges to perform unauthorized actions.
Business impact
Successful exploitation allows an attacker to elevate their account permissions, potentially resulting in full administrative control over the WordPress instance. Given the CVSS score of 8.8, this poses a high risk of total system compromise, including unauthorized data access, modification of site content, and the potential for further malicious code execution.
Remediation
Immediate Action: Administrators should immediately audit user accounts for unauthorized privilege changes and restrict access to the affected plugin until a vendor-supplied patch is confirmed and applied.
Proactive Monitoring: Security teams should monitor WordPress user activity logs for suspicious account modifications or unauthorized administrative actions performed by low-privileged users.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting the cubewp-framework plugin endpoints.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the severity of this privilege escalation flaw, organizations currently running versions 1.1.24 or earlier of the CubeWP Framework must treat this as a high-priority incident. Until a formal security update is verified, restrict access to the plugin or deactivate it if it is not business-critical to prevent potential unauthorized administrative access.
Sources
Originally found and disclosed by Martino Spagnuolo (r3verii) | Patchstack Bug Bounty Program, per the CVE Program record.