CVE-2026-17018 PUBLISHED

CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR

Assigner: WPScan
Reserved: 24.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.

Product Status

Vendor Unknown
Product CubeWP Framework
Versions Default: unknown
  • affected from 0 to 1.1.30 (incl.)

Credits

  • Muni Nitish Kumar Yaddala finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE