CVE-2026-15248
MEDIUMMeta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
Title source: cnaDescription
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/a101136d-606f-4529-ae78-a4fff7724e2c/
Scores
CVSS v3
5.5
EPSS
0.0028
EPSS Percentile
20.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (1)
None/Meta Box
< 5.13.1
Published
Aug 02, 2026
Tracked Since
Aug 02, 2026