PT-2026-65769 · WordPress · Meta Box Aio
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Meta Box AIO versions prior to 3.8.1
Description
The MB Frontend Submission extension contains a missing authorization flaw within the
template redirect dispatcher. The handle request() function routes the mbfs delete action without verifying user capabilities or ownership. Additionally, nonce verification in check ajax() is only performed if is ajax() is true, which is not the case for template redirect requests, allowing the check to be bypassed. Consequently, unauthenticated attackers can delete arbitrary posts and pages by providing a specific post ID through the rwmb frontend field object id GET parameter on any page hosting a frontend submission form, even if the allow delete setting is disabled.Recommendations
Update to a version newer than 3.8.0.
Restrict access to the
rwmb frontend field object id parameter in the affected API endpoint until the update is applied.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meta Box Aio