CVE-2026-39468
WordPress Meta Box – WordPress Custom Fields Framework plugin <= 5.11.1 - Arbitrary File Deletion vulnerability
Record summary
CVE-2026-39468 has a selected CVSS score of 6.8 (medium); EIP currently links 1 Nuclei template.
Description
Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 16, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Meta Box – WordPress Custom Fields FrameworkBrowse eLightUp / Meta Box – WordPress Custom Fields Frameworkmeta-boxDefault status: unaffected | CVE List | Through 5.11.1 | affected |
Nuclei templates
1ProjectDiscoveryHIGHMeta Box <= 5.11.1 - Arbitrary File DeletionCVSS 7.2
The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_delete_file function. This makes it possible for authenticated attackers with Contributor-level access and above to delete arbitrary files on the server.
Impact
Authenticated attackers can delete arbitrary files such as wp-config.php, which can lead to remote code execution in the right configuration.
Remediation
Update Meta Box to version 5.11.2 or later.
Source: ProjectDiscovery