What is CVE-2026-15248?
CVE-2026-15248 is a vulnerability in the Meta Box WordPress plugin before version 5.13.1. It allows users with low-privilege roles, such as Contributor, to permanently delete arbitrary media attachments belonging to other users without proper authorization checks. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-15248 Meta Box WordPress plugin-in 5.13.1-dən əvvəlki versiyalarında aşkar edilmiş zəiflikdir. Bu boşluq Contributor kimi aşağı səlahiyyətli istifadəçilərə authorization yoxlaması olmadan digər istifadəçilərə məxsus media fayllarını qalıcı olaraq silməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What versions of the Meta Box plugin are affected by CVE-2026-15248?
CVE-2026-15248 was discovered in versions of the Meta Box WordPress plugin before 5.13.1.
What can a user with the Contributor role do through this vulnerability?
Users with low-privilege roles, such as Contributor, can permanently delete arbitrary media attachments belonging to other users without proper authorization checks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.