THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-17017 — The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perfor

[NVD] CVE-2026-17017 — The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perfor

mednvdPublished 2026-08-09

CVE-2026-17017 CVSS: None Published: 2026-08-09T06:18:17.940

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17017