CVE-2025-12129

CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Information Exposure

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.27 via the /cubewp-posts/v1/query-new and /cubewp-posts/v1/query REST API endpoints due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.


We have discovered 405 live websites that are affected by CVE-2025-12129.

Run a Free Instant Scan




Affected Software

Product  Cubewp Framework
Category Wordpress Plugins
Vulnerable Domains405 live websites (91% of Cubewp Framework install base)
Vulnerable Versions
  • from 0 through 1.1.27
Vulnerable Versions Count13 versions ( 93% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Jan 17, 2026
  • Updated - Jan 20, 2026

Credits

  • Jonas Benjamin Friedli (finder)

Website Distribution by Country

Number of websites using CVE-2025-12129
United States146 websites



Germany34 websites
Cyprus25 websites
GB23 websites
France15 websites
South Africa14 websites
Australia13 websites
Canada13 websites
Spain11 websites
India10 websites

Website Distribution by TLD

Number of websites using CVE-2025-12129
.com220 websites
.org16 websites
.net16 websites
.de12 websites
.co.uk9 websites
.com.au8 websites
.pl7 websites
.it6 websites
.ca5 websites
.fr4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-12129

Top websites that are affected by CVE-2025-12129. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************************.org Singapore***,***
*******.com Germany***,***
**********.***.au Australia*,***,***
*************.com United States*,***,***
********.com United States*,***,***
**********.**.za South Africa*,***,***
********.**.za South Africa*,***,***
************.com United States*,***,***
***************.com United States*,***,***
******.fr France*,***,***
See full domain list

FAQ

CVE-2025-12129 is Exposure of Sensitive Information to an Unauthorized Actor in Cubewp Framework
A total of 405 websites have been identified as vulnerable to CVE-2025-12129, based on global website indexing conducted by WebTechSurvey.
The Cubewp Framework is affected by the CVE-2025-12129 vulnerability.
Cubewp Framework versions up to and including 1.1.27 are vulnerable to CVE-2025-12129.