CVE-2026-15248: Unknown Meta Box
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.
Affected products
- Unknown Meta Box: before 5.13.1 (fixed in 5.13.1)
Published 2026-08-02. Last modified 2026-08-26.