What the vulnerability does
01Description
The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient input sanitization in the cubewp_remove_relation() AJAX function, specifically the use of wp_unslash() on the relation_id parameter before interpolating it directly into a raw SQL query without using $wpdb->prepare(). The wp_unslash() call explicitly removes the backslash escaping that WordPress's wp_magic_quotes() adds to all $_POST data, neutralizing the only layer of SQL injection protection. The sanitize_text_field() function applied afterward offers no SQL protection. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries to the existing query.
Explanation of Vulnerability in Simple Terms
02Summary
CubeWP Framework versions up to 1.1.30 contain a SQL injection vulnerability in database query handling. An authenticated user with low privileges can craft malicious input to read sensitive data from the database without modifying or deleting records. The vulnerability requires valid site access but no special user interaction.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site database, such as user credentials or configuration details.
Potential impact on your site
04Site Impact
User data and site configuration may be exposed to anyone with basic site access.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege authenticated account on the site.
Key dates
06Disclosure timeline
August 1, 2026
CVE published