Metabox
Metabox Meta BOX: vulnerabilidades y CVE
Metabox Meta BOX tiene 8 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15248 | Media (5.5) | 0.38% | — | 2 ago 2026 | The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently… |
| CVE-2026-39468 | Media (6.8) | 1.3% | — | 15 jun 2026 | Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions. |
| CVE-2025-14675 | Alta (7.2) | 2.4% | — | 7 mar 2026 | The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. This makes it possible… |
| CVE-2024-43235 | Alta (7.1) | 0.47% | — | 1 nov 2024 | Missing Authorization vulnerability in MetaBox.Io Meta Box – WordPress Custom Fields Framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta Box – WordPress Custom… |
| CVE-2024-1204 | Media (4.3) | 0.51% | — | 15 abr 2024 | The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts. |
| CVE-2023-6526 | Media (5.4) | 0.41% | — | 5 feb 2024 | The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta values displayed through the plugin's shortcode in all versions up to, and… |
| CVE-2019-14794 | Alta (7.5) | 1.4% | — | 9 ago 2019 | The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders. |
| CVE-2019-14793 | Media (6.5) | 1.7% | — | 9 ago 2019 | The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter. |