CVE-2026-6453 MEDIUM

CVE-2026-6453: CubeWP Framework <= 1.1.30 - Authenticated (Subscriber+) SQL Injection via 'relation_id' Parameter

Vendor Cubewp1211
Product CubeWP Framework
Weakness CWE-89 · SQLi
Published August 1, 2026
Last update August 1, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient input sanitization in the cubewp_remove_relation() AJAX function, specifically the use of wp_unslash() on the relation_id parameter before interpolating it directly into a raw SQL query without using $wpdb->prepare(). The wp_unslash() call explicitly removes the backslash escaping that WordPress's wp_magic_quotes() adds to all $_POST data, neutralizing the only layer of SQL injection protection. The sanitize_text_field() function applied afterward offers no SQL protection. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries to the existing query.

Explanation of Vulnerability in Simple Terms

02Summary

CubeWP Framework versions up to 1.1.30 contain a SQL injection vulnerability in database query handling. An authenticated user with low privileges can craft malicious input to read sensitive data from the database without modifying or deleting records. The vulnerability requires valid site access but no special user interaction.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the site database, such as user credentials or configuration details.

Potential impact on your site

04Site Impact

User data and site configuration may be exposed to anyone with basic site access.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege authenticated account on the site.

Key dates

06Disclosure timeline

August 1, 2026 CVE published

Related vulnerabilities

08Related CVE