{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cubewp-framework--1.1.30/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-13339"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CubeWP Framework (\u003c= 1.1.30)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","vulnerability"],"_cs_type":"advisory","_cs_vendors":["CubeWP"],"content_html":"\u003cp\u003eThe CubeWP Framework plugin for WordPress (versions 1.1.30 and below) contains a critical path traversal vulnerability within the 'cubewp_get_svg_content' function. This flaw allows unauthenticated attackers to read sensitive files from the underlying server filesystem. The vulnerability is highly accessible because the necessary security nonce, which should protect the AJAX endpoint, is publicly embedded in the HTML markup of pages utilizing CubeWP posts shortcodes or widgets with AJAX loading enabled. An attacker can harvest this nonce as a guest visitor and subsequently craft a malicious AJAX request to exfiltrate configuration files, credentials, or other sensitive system data. This flaw highlights the risks associated with improper nonce exposure in client-side code, which effectively nullifies the authentication mechanism intended to protect sensitive server-side functions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform arbitrary file reads on the web server. This can lead to the exposure of sensitive files such as 'wp-config.php', which typically contains database credentials, authentication keys, and salt values. In environments where the web server process has broader filesystem permissions, this access may facilitate further compromise or full system takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the CubeWP Framework plugin to the latest version immediately to patch the 'cubewp_get_svg_content' function.\u003c/li\u003e\n\u003cli\u003eImplement WAF rules to inspect and block incoming HTTP requests targeting the vulnerable AJAX endpoint with path traversal patterns (e.g., '../').\u003c/li\u003e\n\u003cli\u003eReview web server logs for high-frequency access to sensitive configuration files originating from public IP addresses.\u003c/li\u003e\n\u003cli\u003eAudit all WordPress plugins for similar nonce-exposure issues where security tokens are embedded in public-facing HTML.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-02T01:08:17Z","date_published":"2026-08-02T01:08:17Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cubewp-traversal/","summary":"An unauthenticated directory traversal vulnerability in the CubeWP Framework plugin allows attackers to read arbitrary files by leveraging exposed AJAX nonces.","title":"Arbitrary File Read Vulnerability in CubeWP Framework","url":"https://feed.craftedsignal.io/briefs/2026-08-cubewp-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - CubeWP Framework (\u003c= 1.1.30)","version":"https://jsonfeed.org/version/1.1"}