CVE-2026-15248: Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15248?
CVE-2026-15248 has a risk score of 43, indicating a moderate level of severity.
How do I fix CVE-2026-15248?
To fix CVE-2026-15248, update the Meta Box WordPress plugin to version 5.13.1 or later.
Who is affected by CVE-2026-15248?
CVE-2026-15248 affects users of the Meta Box WordPress plugin prior to version 5.13.1, particularly those with low-privilege roles like Contributor.
What type of vulnerability is CVE-2026-15248?
CVE-2026-15248 is an Insecure Direct Object Reference (IDOR) vulnerability that allows unauthorized deletion of media attachments.
Can contributors exploit CVE-2026-15248?
Yes, users with Contributor roles can exploit CVE-2026-15248 to delete arbitrary media attachments belonging to other users.