CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation (CVE-2026-17017) | HOL Guard CVE