Arbitrary Option Manipulation in CMB2 WordPress Plugin
CVE-2026-80338

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
24 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-80338?

The CMB2 WordPress plugin before version 2.13.0 lacks necessary capability checks on specific AJAX actions. This flaw permits users with minimal permissions, such as Subscribers, to create or modify arbitrary WordPress options, potentially leading to the corruption of critical site settings. Such unauthorized changes can disrupt website functionality and may cause the site to go offline. The exploitation of this vulnerability relies on the presence of declared oEmbed fields from the CMB2 plugin or other compatible WordPress plugins, as CMB2 does not register any by default. Notably, the stored value is not under attacker control; therefore, the issue does not facilitate privilege escalation.

Affected Version(s)

CMB2 0 < 2.13.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mutantgun
WPScan
.