What is CVE-2026-17017?
The CubeWP Framework WordPress plugin (versions before 1.1.31) contains an SQL injection vulnerability due to improper sanitization and missing capability checks on an AJAX action. This allows users with Subscriber-level access or higher to execute SQL injection attacks. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: CubeWP Framework WordPress plagini (1.1.31-dən əvvəlki versiyalar) AJAX əməliyyatında parametri SQL sorğusunda istifadə etməzdən əvvəl düzgün təmizləmədiyi və imtiyaz yoxlaması aparmadığı üçün SQL injection zəifliyinə malikdir. Bu, Subscriber səviyyəsindəki istifadəçilərə verilənlər bazasına hücum etməyə imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
To which version should the CubeWP Framework plugin be updated to fix the SQL injection vulnerability?
The plugin should be updated to version 1.1.31 or higher, as the vulnerability exists in versions before 1.1.31.
What is the minimum privilege level required for an attacker to exploit this vulnerability?
The attacker must have Subscriber-level access or higher to exploit the SQL injection vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.