Arbitrary File Deletion in Meta Box WordPress Plugin by Meta Box
CVE-2026-39468
6.8MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 June 2026
What is CVE-2026-39468?
The Meta Box plugin for WordPress versions up to 5.11.1 is susceptible to an arbitrary file deletion vulnerability. This flaw allows unauthorized users to delete files from the server, potentially leading to data loss and service disruption. It is crucial for users of this plugin to apply the latest updates and monitor their installations to prevent exploitation.
Affected Version(s)
Meta Box β WordPress Custom Fields Framework <= 5.11.1