MEDIUM
cubewp1211
CVE published 2026-08-01
CVE-2026-6453
The CubeWP Framework plugin for WordPress has a SQL injection vulnerability due to insufficient input sanitization in the cubewp_remove_relation() AJAX function. This allows authenticated attackers to append additional SQL queries. The CVE record was published on 2026-08-01T09:17:02.530Z and has not been modified since then. Evidence is limited to public CVE and NVD details. Defenders should verify affect [truncated]