PT-2026-96644 · WordPress · Meta Box Aio+2
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Meta Box AIO versions prior to 3.11.1
Meta Box Frontend Submission versions prior to 4.5.7
Meta Box User Profile versions prior to 3.11.1
Description
A chained flaw allows unauthenticated attackers to escalate privileges to Administrator. The issue begins in the mb-frontend-submission component, where the
populate via query string() function overrides the form's target object id using the GET parameter rwmb frontend field object id without authorization checks. Additionally, the Form::process() function lacks the user can edit() check, enabling attackers to overwrite the post content of any page with an arbitrary shortcode via wp update post(). Subsequently, the mb-user-profile component trusts the role and auto login attributes within the injected [mb user profile register] shortcode without role validation, allowing the attacker to gain administrative access.Recommendations
Update Meta Box AIO to a version newer than 3.11.0.
Update Meta Box Frontend Submission to a version newer than 4.5.6.
Update Meta Box User Profile to a version newer than 3.11.0.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meta Box Aio
Meta Box Frontend Submission
Meta Box User Profile