SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15248

MEDIUM · CVSS 5.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The Meta Box WordPress plugin prior to version 5.13.1 is vulnerable as it fails to properly verify user authorization for deleting media attachments, enabling low-privilege users, like Contributors, to delete arbitrary attachments belonging to other users. This security flaw can lead to unauthorized data loss and disruption of content management. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-15248
Severity
MEDIUM
CVSS
5.5
EPSS
0.28%
WordPress

Original NVD Description

The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.