توضیحات
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
تغییرات این نسخه
= 1.1.31 2026-07-30
SECURITY: Fixed a SQL injection vulnerability in the cubewp_remove_relation AJAX action by casting request IDs to integers, using prepared statements, and adding a capability check on the object the relation belongs to. Reported by Muni Nitish Kumar Yaddala.
SECURITY: Fixed an arbitrary post and user meta disclosure (IDOR) in the cubewp-custom-fields/v1/render REST route by adding per-object read authorization and restricting requests to registered CubeWP custom fields. Reported by Muni Nitish Kumar Yaddala.
SECURITY: Fixed a path traversal issue (CVE-2026-13339) that allowed arbitrary local files to be read through slider arrow icon parameters. Icon files are now restricted to .svg files inside the uploads or plugin directory, with the resolved path canonicalised and containment verified before reading. Reported by Nhien Pham (nhienit) of GalaxyOne.
SECURITY: Fixed a cross-site scripting issue where search filter hidden field values were output without escaping.
ADDED: New CubeWP Users Widget for Elementor and cubewp_shortcode_users shortcode to display users with filtering by roles, specific IDs, current user, or post author, including slider, grid, and boxed view layouts.
ADDED: CubeWP typography settings are now available inside the Elementor typography control, allowing site-wide font variables to be selected on any Elementor widget.
ADDED: Responsive font size options (Desktop, Tablet, and Mobile) for typography settings in CubeWP Settings.
A
SECURITY: Fixed a SQL injection vulnerability in the cubewp_remove_relation AJAX action by casting request IDs to integers, using prepared statements, and adding a capability check on the object the relation belongs to. Reported by Muni Nitish Kumar Yaddala.
SECURITY: Fixed an arbitrary post and user meta disclosure (IDOR) in the cubewp-custom-fields/v1/render REST route by adding per-object read authorization and restricting requests to registered CubeWP custom fields. Reported by Muni Nitish Kumar Yaddala.
SECURITY: Fixed a path traversal issue (CVE-2026-13339) that allowed arbitrary local files to be read through slider arrow icon parameters. Icon files are now restricted to .svg files inside the uploads or plugin directory, with the resolved path canonicalised and containment verified before reading. Reported by Nhien Pham (nhienit) of GalaxyOne.
SECURITY: Fixed a cross-site scripting issue where search filter hidden field values were output without escaping.
ADDED: New CubeWP Users Widget for Elementor and cubewp_shortcode_users shortcode to display users with filtering by roles, specific IDs, current user, or post author, including slider, grid, and boxed view layouts.
ADDED: CubeWP typography settings are now available inside the Elementor typography control, allowing site-wide font variables to be selected on any Elementor widget.
ADDED: Responsive font size options (Desktop, Tablet, and Mobile) for typography settings in CubeWP Settings.
A