CVE-2026-13339: CubeWP Framework Plugin Directory Traversal Vulnerability
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30. This allows unauthenticated attackers to read arbitrary files on the server, potentially exposing sensitive information. A CVSS score of 7.5 indicates a high severity vulnerability.