๐Ÿ” CVE Alert

CVE-2026-17017

UNKNOWN 0.0

CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks.

Vendor unknown
Product cubewp framework
Published Aug 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown cubewp framework

Be the first to know when new unknown vulnerabilities affecting unknown cubewp framework are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / CubeWP Framework
0 < 1.1.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/50d95281-7b3f-4d5a-bf04-8e7bd88f4b55/

Credits

Muni Nitish Kumar Yaddala WPScan