CVE-2026-17018
CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.
| Vendor | unknown |
| Product | cubewp framework |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown cubewp framework
Be the first to know when new unknown vulnerabilities affecting unknown cubewp framework are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / CubeWP Framework
0 โค 1.1.30
References
Credits
Muni Nitish Kumar Yaddala WPScan