VDB
Sign up
HIGH7.2

GHSA-m4q3-832v-44j6

Meta Box Plugin for WordPress: Authenticated (Contributor+) Arbitrary File Deletion via ajax_delete_file

Quick fix

GHSA-m4q3-832v-44j6 — wpmetabox/meta-box: upgrade to the fixed version with the command below.

composer require wpmetabox/meta-box:^5.11.2

Details

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/wpmetabox/meta-box
Introduced in: 0Fixed in: 5.11.2
Fixcomposer require wpmetabox/meta-box:^5.11.2

References