Record summary

CVE-2026-39468 has a selected CVSS score of 6.8 (medium); EIP currently links 1 Nuclei template.

Description

Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 16, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Meta Box – WordPress Custom Fields Framework

Browse eLightUp / Meta Box – WordPress Custom Fields Frameworkmeta-box

Default status: unaffected

CVE ListThrough 5.11.1affected

Nuclei templates

1
ProjectDiscoveryHIGHMeta Box <= 5.11.1 - Arbitrary File DeletionCVSS 7.2

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_delete_file function. This makes it possible for authenticated attackers with Contributor-level access and above to delete arbitrary files on the server.

Impact

Authenticated attackers can delete arbitrary files such as wp-config.php, which can lead to remote code execution in the right configuration.

Remediation

Update Meta Box to version 5.11.2 or later.

WeaknessesCWE-22
Authorsiamatownboy
Template tagscvecve2026wordpresswpwp-pluginmeta-boxfile-deletionpassive
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

2