CVE-2026-13339
The CubeWP Framework plugin for WordPress contains a security flaw in versions up to 1.1.30 that allows unauthorized access to server files. This issue arises from the 'cubewp_get_svg_content' function, which can be exploited to reveal sensitive information contained within arbitrary files on the server. Unauthenticated users can leverage this vulnerability by obtaining the required nonce through public emission in page markup, facilitating subsequent exploitation of the Directory Traversal flaw.
Based on public CVE data (MITRE/NVD).