PT-2026-65769 · Meta Box · Meta Box Aio

·

CVE-2026-14488

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle request() function routing the mbfs delete action without any capability or ownership check, and the nonce verification in check ajax() being gated behind is ajax() which is false for template redirect requests, making it bypassable. This makes it possible for unauthenticated attackers to delete arbitrary posts and pages by supplying an attacker-controlled post ID via the rwmb frontend field object id GET parameter on any page that hosts a frontend submission form regardless of whether allow delete is enabled.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14488

Affected Products

Meta Box Aio