VYPR

Meta Box AIO

by WordPress

CVEs (1)

  • CVE-2026-14488Jul 29, 2026
    risk 0.00cvss epss 0.00

    The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without…