Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.1
CVE-2026-17017: CubeWP Framework SQL Injection via Unchecked User Access
CVE-2026-17017 · published 26 days ago
Summary
The CubeWP Framework plugin for WordPress has a security flaw that could allow attackers to manipulate database queries, potentially leading to unauthorized access or data tampering. This affects all users with Subscriber-level access or higher. To protect your site, update the plugin to version 1.1.31 or later.
What to do
- Update unknown cubewp framework to version 1.1.31 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | cubewp framework | < 1.1.31 |
Original advisory text
CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation
The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks.
References
- https://wpscan.com/vulnerability/50d95281-7b3f-4d5a-bf04-8e7bd88f4b55/ exploit vdb-entry technical-description
Severity
8.1
High
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published9 Aug 2026
Updated24 Aug 2026
First seen9 Aug 2026
Monitor software like this
Free during beta