A vulnerability was found in Imran Tauqeer CubeWP Plugin up to 1.1.30 on WordPress. It has been declared as critical. The affected element is an unknown function. The manipulation results in sql injection.
This vulnerability is reported as CVE-2026-28168. The attack can be launched remotely. No exploit exists.