Medium severity5.5NVD Advisory· Published Aug 2, 2026· Updated Aug 26, 2026
CVE-2026-15248
CVE-2026-15248
Description
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<5.13.1+ 1 more
- (no CPE)range: <5.13.1
- (no CPE)range: <5.13.1
Patches
Vulnerability mechanics
References
1News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)Wordfence Blog · Aug 14, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)Wordfence Blog · Aug 8, 2026