Unrated severityNVD Advisory· Published Aug 2, 2026
Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
CVE-2026-15248
Description
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<5.13.1+ 1 more
- (no CPE)range: <5.13.1
- (no CPE)range: <5.13.1
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/a101136d-606f-4529-ae78-a4fff7724e2c/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.