PatchSiren

CubeWP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM CubeWP CVE published 2026-08-10

CVE-2026-17018

The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints. This vulnerability allows users with the Contributor role and above to read arbitrary post metadata, including that of other users' draft, pending, private, and password-protected posts, and arbitrary user metadata [truncated]

HIGH CubeWP CVE published 2026-08-09

CVE-2026-17017

The CubeWP Framework WordPress plugin before 1.1.31 has a SQL injection vulnerability. This vulnerability allows users with Subscriber-level access and above to perform SQL injection attacks through an AJAX action, potentially leading to unauthorized access or data breaches. The CVE record was published on 2026-08-09T06:18:17.940Z. It is essential to verify the CubeWP Framework WordPress plugin version an [truncated]