WP Clinic
Log in Sign up

CVE · High

CVE-2025-14675 — Meta Box [meta-box] < 5.11.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14675 Meta Box [meta-box] < 5.11.2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.2 < 5.11.2 5.11.2 2026-03-06

CVE-2025-14675

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.