CVE-2019-14794: High severity metabox.io meta box vulnerability
Published Aug 9, 2019
·Updated
The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders.
Affected Software
1 affected component
Metabox Meta Box Wordpress<4.16.2
Event History
Aug 9, 2019
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14794?
CVE-2019-14794 is rated as a medium severity vulnerability.
2
How do I fix CVE-2019-14794?
To fix CVE-2019-14794, update the Meta Box plugin to version 4.16.2 or later.
3
What kind of files are affected by CVE-2019-14794?
CVE-2019-14794 affects the uploading of files to custom folders in the Meta Box plugin.
4
What versions of the Meta Box plugin are vulnerable to CVE-2019-14794?
All versions of the Meta Box plugin prior to 4.16.2 are vulnerable to CVE-2019-14794.
5
Is the Meta Box plugin affected by CVE-2019-14794 on all WordPress installations?
Yes, CVE-2019-14794 affects any WordPress installation using the vulnerable version of the Meta Box plugin.