CVE-2026-28168: WordPress CubeWP plugin <= 1.1.30 - SQL Injection vulnerability
Published Aug 13, 2026
·Updated
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
Affected Software
1 affected component
CubeWP<=1.1.30
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress CubeWP pluginto a version that resolves this vulnerability.Fixed in 1.1.31
Event History
Aug 13, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28168?
CVE-2026-28168 has a severity rating of 8.5, categorized as high.
2
How do I fix CVE-2026-28168?
To address CVE-2026-28168, update the CubeWP plugin to a version later than 1.1.30.
3
What type of vulnerability is CVE-2026-28168?
CVE-2026-28168 is an SQL Injection vulnerability affecting the CubeWP plugin.
4
Which versions of CubeWP are affected by CVE-2026-28168?
CubeWP versions 1.1.30 and earlier are vulnerable to CVE-2026-28168.
5
What are the potential risks of CVE-2026-28168?
CVE-2026-28168 may allow attackers to execute unauthorized SQL queries, potentially compromising sensitive data.