CVE-2026-14488
Meta Box Meta Box AIO
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without any capability or ownership check, and the nonce verification in check_ajax() being gated behind is_ajax() which is false for template_redirect requests, making it bypassable. This makes it possible for unauthenticated attackers to delete arbitrary posts and pages by supplying an attacker-controlled post ID via the r...
- CVSS
- 9.1
- EPSS
- 0.31% 23.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.29