CVE-2025-30994

WordPress CubeWP – All-in-One Dynamic Content Framework plugin <= 1.1.23 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Emraan Cheema CubeWP – All-in-One Dynamic Content Framework allows Cross Site Request Forgery. This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.23.


We have discovered 494 live websites that are affected by CVE-2025-30994.

Run a Free Instant Scan




Affected Software

Product  Cubewp Framework
Category Wordpress Plugins
Vulnerable Domains494 live websites (100% of Cubewp Framework install base)
Vulnerable Versions
  • from 0 through 1.1.23
Vulnerable Versions Count14 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jun 6, 2025
  • Updated - Jun 6, 2025

Credits

  • Nguyen Tran Tuan Dung (domiee13) (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-30994
United States199 websites



Germany47 websites
Cyprus46 websites
GB34 websites
France19 websites
South Africa14 websites
Australia10 websites
Spain10 websites
Canada10 websites
Singapore9 websites

Website Distribution by TLD

Number of websites using CVE-2025-30994
.com260 websites
.org24 websites
.net20 websites
.co.uk12 websites
.de11 websites
.ca9 websites
.fr8 websites
.pl8 websites
.com.au8 websites
.it8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-30994

Top websites that are affected by CVE-2025-30994. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.ca Canada***,***
*********************.ch Switzerland***,***
************************.org United States***,***
***********.com Cyprus***,***
**********.***.au United States*,***,***
*************.com United States*,***,***
*********.com United States*,***,***
***********.de Germany*,***,***
********.com United States*,***,***
**********.**.za South Africa*,***,***
See full domain list

FAQ

CVE-2025-30994 is Cross-Site Request Forgery (CSRF) in Cubewp Framework
A total of 494 websites have been identified as vulnerable to CVE-2025-30994, based on global website indexing conducted by WebTechSurvey.
The Cubewp Framework is affected by the CVE-2025-30994 vulnerability.
Cubewp Framework versions up to and including 1.1.23 are vulnerable to CVE-2025-30994.