AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-17018

MEDIUM · CVSS 4.9 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The CubeWP Framework WordPress plugin versions up to 1.1.30 lack proper authorization checks on a REST API endpoint, enabling users with Contributor roles and higher to access arbitrary post metadata, including private and protected content, as well as sensitive user metadata. This vulnerability poses a significant risk of unauthorized data exposure, particularly affecting user privacy and content confidentiality. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate potential data breaches.

CVE
CVE-2026-17018
Severity
MEDIUM
CVSS
4.9
EPSS
0.22%
WordPress

Original NVD Description

The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.