CVE Database /
CVE-2026-17018
CVE
CVE-2026-17018 — CubeWP Framework [cubewp-framework] <= 1.1.30 (unfixed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-17018
|
CubeWP Framework [cubewp-framework] <= 1.1.30 (unfixed) |
Authorization Bypass Through User-Controlled Key |
Unknown
|
< 1.1.30
|
1.1.30 |
2026-08-10 |
—
|
CVE-2026-17018
The CubeWP Framework WordPress plugin's REST API endpoint fails to enforce access controls for metadata retrieval, enabling users with Contributor privileges or higher to view sensitive data from various post types and user profiles without proper authorization. This vulnerability affects the plugin up to version 1.1.30. Affected users can access private posts and other restricted content.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings