CVE

CVE-2026-17018 — CubeWP Framework [cubewp-framework] <= 1.1.30 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-17018 CubeWP Framework [cubewp-framework] <= 1.1.30 (unfixed) Authorization Bypass Through User-Controlled Key Unknown < 1.1.30 1.1.30 2026-08-10

CVE-2026-17018

The CubeWP Framework WordPress plugin's REST API endpoint fails to enforce access controls for metadata retrieval, enabling users with Contributor privileges or higher to view sensitive data from various post types and user profiles without proper authorization. This vulnerability affects the plugin up to version 1.1.30. Affected users can access private posts and other restricted content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.