PT-2026-65769 · WordPress · Meta Box Aio

·

CVE-2026-14488

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Meta Box AIO versions prior to 3.8.1
Description The MB Frontend Submission extension contains a missing authorization flaw within the template redirect dispatcher. The handle request() function routes the mbfs delete action without verifying user capabilities or ownership. Additionally, nonce verification in check ajax() is only performed if is ajax() is true, which is not the case for template redirect requests, allowing the check to be bypassed. Consequently, unauthenticated attackers can delete arbitrary posts and pages by providing a specific post ID through the rwmb frontend field object id GET parameter on any page hosting a frontend submission form, even if the allow delete setting is disabled.
Recommendations Update to a version newer than 3.8.0. Restrict access to the rwmb frontend field object id parameter in the affected API endpoint until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14488

Affected Products

Meta Box Aio