CVE Database /
CVE-2026-17017
CVE
CVE-2026-17017 — CubeWP Framework [cubewp-framework] < 1.1.31
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-17017
|
CubeWP Framework [cubewp-framework] < 1.1.31 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Unknown
|
< 1.1.31
|
1.1.31 |
2026-08-09 |
—
|
CVE-2026-17017
A vulnerability exists in the CubeWP Framework WordPress plugin prior to version 1.1.31, where user input is inadequately sanitized before being integrated into database queries via an AJAX function. This oversight enables individuals with a subscriber role or higher to execute malicious SQL commands, compromising the security of the affected system.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings