CVE-2026-13339 Details
Description
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is exploitable by unauthenticated attackers because the required nonce is publicly emitted into the markup of any page rendering the CubeWP posts shortcode or widget with AJAX loading enabled, making it harvestable by any guest visitor before submitting the AJAX request.
A directory traversal vulnerability has been identified in the CubeWP Framework plugin for WordPress, affecting all versions through 1.1.30. The issue arises in the 'cubewp_get_svg_content' function, where unauthenticated attackers can exploit the vulnerability to read arbitrary files on the server, potentially accessing sensitive information. The vulnerability is made possible because the required nonce is publicly available in the markup of any page that uses the CubeWP posts shortcode or widget with AJAX loading enabled. This allows guest visitors to collect the nonce before submitting the AJAX request, facilitating the exploitation.
Users are advised to update the CubeWP Framework plugin to version 1.1.31 or a newer patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 2, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CubeWP Framework | <= 1.1.30 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 2, 2026 | New CVE Received | [email protected] |
Volerion