PatchSiren

CubeWP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review CubeWP CVE published 2026-08-09

CVE-2026-17017

The CubeWP Framework WordPress plugin before 1.1.31 has a SQL injection vulnerability. This vulnerability allows users with Subscriber-level access and above to perform SQL injection attacks through an AJAX action, potentially leading to unauthorized access or data breaches. The CVE record was published on 2026-08-09T06:18:17.940Z. It is essential to verify the CubeWP Framework WordPress plugin version an [truncated]