


Perceptive Security
SOC/SIEM Consultancy

The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in ver…
Published:
28 July 2026 at 22:00:00
Alert date:
29 July 2026 at 12:00:58
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-14488 affects the Meta Box AIO plugin for WordPress, specifically the MB Frontend Submission extension in versions up to and including 3.8.0. The vulnerability is a Missing Authorization flaw in the template_redirect dispatcher. The handle_request() function routes the mbfs_delete action without any capability or ownership verification. Additionally, nonce verification in check_ajax() is bypassed because is_ajax() returns false for template_redirect requests. This allows unauthenticated attackers to delete arbitrary posts and pages by supplying an attacker-controlled post ID via the rwmb_frontend_field_object_id GET parameter. The attack can be executed on any page hosting a frontend submission form, regardless of whether the allow_delete option is enabled. This represents a critical content integrity risk for WordPress sites using this plugin.
Technical details
Mitigation steps:
Affected products:
Meta Box AIO plugin for WordPress (MB Frontend Submission extension <= 3.8.0)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14488
https://metabox.io/plugins/meta-box-aio/changelog/
https://www.wordfence.com/threat-intel/vulnerabilities/id/e9506f84-3d33-48e0-8dce-d517e1a923e4?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
