
Qubely – Advanced Gutenberg Blocks Security & Risk Analysis
wordpress.org/plugins/qubelyReadymade gutenberg blocks and sections with rich customization options. Enhance Gutenberg editor with easy UI and functional blocks.
Is Qubely – Advanced Gutenberg Blocks Safe to Use in 2026?
High Risk
Score 46/100Qubely – Advanced Gutenberg Blocks carries significant security risk with 9 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The Qubely plugin version 1.8.14 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and output escaping, significant concerns arise from its attack surface, particularly its unprotected entry points. The plugin exposes 10 out of 13 total entry points (AJAX handlers and REST API routes) without proper authentication or permission checks, creating a substantial risk for unauthorized access and potential malicious actions. The taint analysis found no critical or high severity unsanitized flows, which is a positive indicator, but the lack of authorization checks on so many entry points can allow attackers to reach vulnerable code paths that might not be apparent in static analysis alone.
The plugin's vulnerability history is deeply concerning, with 9 known medium severity CVEs, two of which remain unpatched. The recurring nature of vulnerabilities, including Missing Authorization and Cross-site Scripting, coupled with the recent discovery of flaws in late 2025, suggests a pattern of security weaknesses that the development team has struggled to consistently address. The presence of unpatched vulnerabilities, even at a medium severity, poses an immediate risk to users. While the plugin has strengths in certain secure coding practices, the high number of unprotected entry points and the persistent vulnerability history present a significant security risk that warrants careful consideration and prompt patching.
Key Concerns
- Unpatched CVEs
- High number of unprotected AJAX handlers
- High number of unprotected REST API routes
- Recurring vulnerability types (Missing Auth, XSS)
Qubely – Advanced Gutenberg Blocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
Qubely <= 1.8.14 - Missing Authorization
Qubely <= 1.8.14 - Authenticated (Contributor+) Sensitive Information Exposure
Qubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content
Qubely – Advanced Gutenberg Blocks <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' and 'UniqueID'
Qubely – Advanced Gutenberg Blocks <= 1.8.5 - Insufficient Authorization
Quebely <= 1.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'className' Block Option
Qubely <= 1.7.9 - Incorrect Authorization
Qubely <= 1.7.8 - Missing Authorization
Qubely <= 1.7.7 - Missing Authorization to Arbitrary Post Deletion
Qubely – Advanced Gutenberg Blocks Code Analysis
Output Escaping
Data Flow Analysis
Qubely – Advanced Gutenberg Blocks Attack Surface
AJAX Handlers 5
REST API Routes 8
WordPress Hooks 29
Maintenance & Trust
Qubely – Advanced Gutenberg Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Qubely – Advanced Gutenberg Blocks Alternatives
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Superb Addons: Blocks, Patterns & Theme Designer for the Block Editor & FSE
superb-blocks
Create beautiful WordPress websites easily with 10+ blocks, 200+ patterns, 100+ pre-built pages, animations and Theme Designer. No coding needed!
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
gutenkit-blocks-addon
GutenKit – Ultimate no-code Gutenberg blocks to design stunning web pages and visually stunning posts in WordPress block editor.
Qubely – Advanced Gutenberg Blocks Developer Profile
14 plugins · 675K total installs
How We Detect Qubely – Advanced Gutenberg Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qubely/assets/css/qubely-styles.css/wp-content/plugins/qubely/assets/css/qubely-editor-styles.css/wp-content/plugins/qubely/assets/js/qubely-block.js/wp-content/plugins/qubely/assets/js/qubely-editor.js/wp-content/plugins/qubely/assets/js/qubely-backend.js/wp-content/plugins/qubely/assets/js/qubely-block.js/wp-content/plugins/qubely/assets/js/qubely-editor.jsqubely/assets/css/qubely-styles.css?ver=qubely/assets/css/qubely-editor-styles.css?ver=qubely/assets/js/qubely-block.js?ver=qubely/assets/js/qubely-editor.js?ver=qubely/assets/js/qubely-backend.js?ver=HTML / DOM Fingerprints
qubely-editor-block<!-- Qubely Block Start --><!-- Qubely Block End -->data-qubely-blockqubely_block_dataqubely_localize/wp-json/qubely