Arbitrary File Deletion Vulnerability in Meta Box Plugin for WordPress
CVE-2025-14675

7.2HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
7 March 2026

What is CVE-2025-14675?

The Meta Box plugin for WordPress contains a vulnerability that allows authenticated users with Contributor-level access and higher to delete arbitrary files on the server. This issue stems from insufficient file path validation within the 'ajax_delete_file' function. If the wrong files, such as critical configuration files, are deleted, it can lead to serious security breaches, including remote code execution. It is crucial for users of the plugin to update to the latest version to protect their sites from potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Meta Box * <= 5.11.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JongHwan Shin
.