CVE

CVE-2026-15248 — Meta Box [meta-box] < 5.13.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15248 Meta Box [meta-box] < 5.13.1 Missing Authorization Unknown < 5.13.1 5.13.1 2026-08-02

CVE-2026-15248

Before version 5.13.1, the Meta Box plugin for WordPress fails to check if a user has permission to delete an uploaded file. This oversight allows users with limited permissions, like Contributors, to remove any media files owned by other users permanently.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.