Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

CVE-2026-17017: CubeWP Framework SQL Injection via Unchecked User Access

CVE-2026-17017 · published 26 days ago
Summary

The CubeWP Framework plugin for WordPress has a security flaw that could allow attackers to manipulate database queries, potentially leading to unauthorized access or data tampering. This affects all users with Subscriber-level access or higher. To protect your site, update the plugin to version 1.1.31 or later.

What to do
  • Update unknown cubewp framework to version 1.1.31 or later.
Affected software
VendorProductAffected versions
unknown cubewp framework < 1.1.31
Original advisory text
CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation
The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks.
References
Severity
8.1 High
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published9 Aug 2026
Updated24 Aug 2026
First seen9 Aug 2026
Sources
CVE-2026-17017 · MITRE
Monitor software like this
Free during beta