CVE-2026-17018

The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-17018

Mitre link : CVE-2026-17018

CVE.ORG link : CVE-2026-17018


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key