cleantalk
Vulnerabilities and Security Researches

CubeWP Forms – LeadGen & Contact Form, CVE-2025-49880

CVE, Research URL

CVE-2025-49880

Published on
Jun 17, 2025
Research Description
Missing Authorization vulnerability in Emraan Cheema CubeWP Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CubeWP Forms: from n/a through 1.1.5.
Affected versions
Min -, max 1.1.6.
Status
vulnerable