Arbitrary File Deletion Vulnerability in Meta Box Plugin for WordPress
CVE-2025-14675
7.2HIGH
What is CVE-2025-14675?
The Meta Box plugin for WordPress contains a vulnerability that allows authenticated users with Contributor-level access and higher to delete arbitrary files on the server. This issue stems from insufficient file path validation within the 'ajax_delete_file' function. If the wrong files, such as critical configuration files, are deleted, it can lead to serious security breaches, including remote code execution. It is crucial for users of the plugin to update to the latest version to protect their sites from potential exploitation.
Affected Version(s)
Meta Box 0 <= 5.11.1