CyberRota Analysis
AI-GeneratedThe CubeWP Framework WordPress plugin versions up to 1.1.30 lack proper authorization checks on a REST API endpoint, enabling users with Contributor roles and higher to access arbitrary post metadata, including private and protected content, as well as sensitive user metadata. This vulnerability poses a significant risk of unauthorized data exposure, particularly affecting user privacy and content confidentiality. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate potential data breaches.
Original NVD Description
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.