Skip to content

Known CVE

WordPress Qubely < 1.8.6 - Unauthenticated Email Sending

Qubely WordPress plugin < 1.8.6 contains an insecure deserialization caused by unauthenticated users being able to send arbitrary emails via the qubely_send_form_data AJAX action, letting attackers send spam or malicious emails, exploit requires no authentication.

CVE-2021-24916

High2021CVSS 5.3CWE-284

cve2021 · wordpress · wp-plugin · qubely · wp · email · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website