HIGH7.2
GHSA-m4q3-832v-44j6
Meta Box Plugin for WordPress: Authenticated (Contributor+) Arbitrary File Deletion via ajax_delete_file
Quick fix
GHSA-m4q3-832v-44j6 — wpmetabox/meta-box: upgrade to the fixed version with the command below.
composer require wpmetabox/meta-box:^5.11.2Details
The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/wpmetabox/meta-box
Introduced in:
0Fixed in: 5.11.2Fix
composer require wpmetabox/meta-box:^5.11.2References
- https://nvd.nist.gov/vuln/detail/CVE-2025-14675[ADVISORY]
- https://github.com/wpmetabox/meta-box/pull/1654[WEB]
- https://github.com/wpmetabox/meta-box/commit/08c6511607b9cc9fe8d0de7a7e91c9d5d415f831[WEB]
- https://github.com/wpmetabox/meta-box[PACKAGE]
- https://plugins.trac.wordpress.org/browser/meta-box/tags/5.11.0/inc/fields/file.php#L30[WEB]
- https://plugins.trac.wordpress.org/browser/meta-box/tags/5.11.0/inc/fields/file.php#L54[WEB]
- https://plugins.trac.wordpress.org/changeset/3475210/meta-box#file3[WEB]
- https://www.wordfence.com/threat-intel/vulnerabilities/id/036467de-95bb-4bfd-9522-df8dc17f3102?source=cve[WEB]