CVE-2019-14793: Metabox Meta Box

Medium severity, CVSS 6.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter.

Affected products

  • Metabox Meta Box: before 4.16.3 (fixed in 4.16.3)

Published 2019-08-09. Last modified 2026-06-17.