๐Ÿ” CVE Alert

CVE-2026-17018

UNKNOWN 0.0

CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.

Vendor unknown
Product cubewp framework
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown cubewp framework

Be the first to know when new unknown vulnerabilities affecting unknown cubewp framework are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / CubeWP Framework
0 โ‰ค 1.1.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/df87c8d0-b3f3-4995-ac95-d63544e71a32/

Credits

Muni Nitish Kumar Yaddala WPScan