The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints. This vulnerability allows users with the Contributor role and above to read arbitrary post metadata, including that of other users' draft, pending, private, and password-protected posts, and arbitrary user metadata [truncated]
The CubeWP Framework WordPress plugin before 1.1.31 has a SQL injection vulnerability. This vulnerability allows users with Subscriber-level access and above to perform SQL injection attacks through an AJAX action, potentially leading to unauthorized access or data breaches. The CVE record was published on 2026-08-09T06:18:17.940Z. It is essential to verify the CubeWP Framework WordPress plugin version an [truncated]