Junglewise Threat Intelligence

CVE-2026-17018: CubeWP Framework IDOR metadata disclosure in REST API

CVE-2026-17018 · Severity: medium · CVSS 4.9 · Published 2026-08-10

Executive brief

The CubeWP Framework WordPress plugin fails to properly check permissions on its custom REST API endpoint for reading post and user metadata. An attacker with a basic Contributor account can read sensitive metadata from other users' private, draft, or password-protected posts—including confidential data belonging to administrators—without legitimate access rights. This exposure can lead to disclosure of proprietary business information and private user data across the entire WordPress site.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) in the REST API endpoint `/cubewp-custom-fields/v1/render`. The plugin fails to perform per-object authorization checks before returning metadata, and does not restrict which metadata keys can be queried. A Contributor-level user (minimum role requirement) can enumerate arbitrary post IDs and field names via authenticated requests, reading any post metadata (including from private/draft posts they cannot edit) and any user metadata. The attack requires valid WordPress authentication (session cookie and REST nonce), but no additional preconditions. The plugin does not restrict access the way WordPress core REST API does. No patch is currently available.

Affected products

  • CubeWP Framework through 1.1.30

Timeline

  • 2026-08-05: disclosed
  • 2026-08-10: advisory

References