What is CVE-2026-14488?
The CVE-2026-14488 vulnerability in the Meta Box AIO WordPress plugin arises from a Missing Authorization issue in the MB Frontend Submission extension, allowing unauthenticated users to delete files via the mbfs_delete action through the template_redirect dispatcher. This affects versions up to and including 3.8.0. Updating the plugin to the latest version is recommended.
Azərbaycanca: Meta Box AIO WordPress plaginində tapılan CVE-2026-14488 zəifliyi MB Frontend Submission uzantısında autorizasiya çatışmazlığı səbəbindən autentifikasiya olunmamış istifadəçilərə mbfs_delete əmri ilə faylları silmək imkanı yaradır. Bu, 3.8.0 və daha əvvəlki versiyalara təsir edir. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Meta Box AIO plugin are affected by CVE-2026-14488?
This vulnerability affects Meta Box AIO plugin versions up to and including 3.8.0.
What does the CVE-2026-14488 vulnerability allow unauthenticated users to do?
The vulnerability allows unauthenticated users to delete files via the mbfs_delete action due to a Missing Authorization issue in the MB Frontend Submission extension.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.