Arbitrary File Deletion Vulnerability in Meta Box Plugin for WordPress
CVE-2025-14675
What is CVE-2025-14675?
The Meta Box plugin for WordPress contains a vulnerability that allows authenticated users with Contributor-level access and higher to delete arbitrary files on the server. This issue stems from insufficient file path validation within the 'ajax_delete_file' function. If the wrong files, such as critical configuration files, are deleted, it can lead to serious security breaches, including remote code execution. It is crucial for users of the plugin to update to the latest version to protect their sites from potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Meta Box * <= 5.11.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved