PT-2026-96644 · WordPress · Meta Box Aio+2

·

CVE-2026-13355

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Meta Box AIO versions prior to 3.11.1 Meta Box Frontend Submission versions prior to 4.5.7 Meta Box User Profile versions prior to 3.11.1
Description A chained flaw allows unauthenticated attackers to escalate privileges to Administrator. The issue begins in the mb-frontend-submission component, where the populate via query string() function overrides the form's target object id using the GET parameter rwmb frontend field object id without authorization checks. Additionally, the Form::process() function lacks the user can edit() check, enabling attackers to overwrite the post content of any page with an arbitrary shortcode via wp update post(). Subsequently, the mb-user-profile component trusts the role and auto login attributes within the injected [mb user profile register] shortcode without role validation, allowing the attacker to gain administrative access.
Recommendations Update Meta Box AIO to a version newer than 3.11.0. Update Meta Box Frontend Submission to a version newer than 4.5.6. Update Meta Box User Profile to a version newer than 3.11.0.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13355

Affected Products

Meta Box Aio
Meta Box Frontend Submission
Meta Box User Profile