CVE-2026-15248
Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.
| Vendor | unknown |
| Product | meta box |
| Published | Aug 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown meta box
Be the first to know when new unknown vulnerabilities affecting unknown meta box are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Meta Box
0 < 5.13.1
References
Credits
Duy WPScan