Arbitrary File Deletion in Meta Box WordPress Plugin by Meta Box
CVE-2026-39468

6.8MEDIUM

What is CVE-2026-39468?

The Meta Box plugin for WordPress versions up to 5.11.1 is susceptible to an arbitrary file deletion vulnerability. This flaw allows unauthorized users to delete files from the server, potentially leading to data loss and service disruption. It is crucial for users of this plugin to apply the latest updates and monitor their installations to prevent exploitation.

Affected Version(s)

Meta Box – WordPress Custom Fields Framework <= 5.11.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.