PT-2026-67027 · WordPress · Cubewp Framework

·

CVE-2026-13339

·

Published

2026-08-01

·

Updated

2026-08-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CubeWP Framework versions prior to 1.1.31
Description The CubeWP Framework plugin for WordPress contains a Directory Traversal flaw within the cubewp get svg content() function. This issue allows unauthenticated attackers to read arbitrary files from the server, potentially exposing sensitive information. The flaw is exploitable because the required nonce is publicly emitted in the markup of pages using the CubeWP posts shortcode or widget with AJAX loading enabled, allowing guest visitors to harvest it before sending the AJAX request via the prev icon or next icon parameters.
Recommendations Update the plugin to a version later than 1.1.30. As a temporary mitigation, disable AJAX loading for CubeWP posts shortcodes or widgets to prevent the public emission of the nonce.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13339

Affected Products

Cubewp Framework