VYPR
Unrated severityNVD Advisory· Published Aug 2, 2026

Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR

CVE-2026-15248

Description

The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.