What is CVE-2026-13339?
The CVE-2026-13339 vulnerability affects the CubeWP Framework plugin for WordPress. Due to a Directory Traversal flaw in the 'cubewp_get_svg_content' function, unauthenticated attackers can read arbitrary sensitive files on the server in all versions up to 1.1.30. The plugin should be updated immediately.
Azərbaycanca: CVE-2026-13339 zəifliyi WordPress-in CubeWP Framework pluginində aşkarlanıb. 1.1.30 versiyasına qədər olan bütün versiyaları təsirləyən bu zəiflik, 'cubewp_get_svg_content' funksiyasındakı Directory Traversal qüsuru səbəbilə autentifikasiya olunmamış hücumçulara serverdəki həssas faylları oxumağa imkan verir. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which WordPress plugin is affected by CVE-2026-13339?
This vulnerability affects the CubeWP Framework plugin for WordPress.
What should be done to protect against CVE-2026-13339?
The plugin should be updated to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.