A vulnerability identified as critical has been detected in cubewp1211 CubeWP Framework Plugin up to 1.1.30 on WordPress. This affects the function cubewp_remove_relation. Performing a manipulation of the argument relation_id results in sql injection.

This vulnerability was named CVE-2026-6453. The attack may be initiated remotely. There is no available exploit.