SQL Injection Vulnerability in CubeWP Framework Plugin for WordPress
CVE-2026-6453
6.5MEDIUM
What is CVE-2026-6453?
The CubeWP Framework plugin for WordPress has an SQL Injection vulnerability stemming from inadequate input sanitization in the cubewp_remove_relation() AJAX function. The use of wp_unslash() on the relation_id parameter allows for raw SQL execution without proper preparation, exposing the system to potential manipulation by authenticated users with subscriber-level access and higher. This flaw compromises data integrity and allows attackers to augment existing queries, emphasizing the need for immediate remediation in affected versions.
Affected Version(s)
CubeWP Framework 0 <= 1.1.30