Skip to content
Threat Feed
critical advisory PoC

Unauthenticated Privilege Escalation in Meta Box AIO for WordPress

An unauthenticated privilege escalation vulnerability (CVE-2026-13355) in the Meta Box AIO plugin allows attackers to overwrite post content with arbitrary shortcodes to register administrative accounts.

CVE search metadata

CVE search record: CVE-2026-13355. Severity: critical. CVSS: 9.8. KEV: no. Product: Meta Box AIO (<= 3.11.0), Meta Box Frontend Submission (<= 4.5.6), Meta Box User Profile (<= 3.11.0), MB Frontend Submission (<= 4.5.6), MB User Profile (<= 3.11.0). Brief: Unauthenticated Privilege Escalation in Meta Box AIO for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-09-meta-box-privilege-escalation/

What's new

  • 1. poc_available Sep 22, 07:38 via sploitus

The Meta Box AIO plugin for WordPress, along with its standalone components Meta Box Frontend Submission and Meta Box User Profile, is affected by a critical vulnerability (CVE-2026-13355) that enables unauthenticated privilege escalation to the Administrator role. The vulnerability exists due to a chained flaw between the mb-frontend-submission and mb-user-profile components.

An attacker can exploit the 'populate_via_query_string()' function, which improperly processes the 'rwmb_frontend_field_object_id' GET parameter without authorization checks. This allows the attacker to overwrite the content of any post on the target WordPress site using 'wp_update_post()'. By injecting a malicious '[mb_user_profile_register]' shortcode into a post, the attacker leverages the mb-user-profile component's failure to validate the 'role' and 'auto_login' shortcode attributes. This process permits the registration or modification of user accounts, granting the attacker administrative access to the WordPress environment. This vulnerability affects Meta Box AIO versions up to 3.11.0, Meta Box Frontend Submission up to 4.5.6, and Meta Box User Profile up to 3.11.0.

Impact

Successful exploitation allows unauthenticated attackers to gain full administrative control over the affected WordPress installation. This can lead to unauthorized access to sensitive site data, modification of content, installation of malicious plugins or themes, and potential lateral movement into the hosting infrastructure.

Recommendation

Prioritize the immediate update of the Meta Box AIO plugin, Meta Box Frontend Submission, and Meta Box User Profile to the latest patched versions released by the vendor. Conduct a forensic audit of posts and pages for unexpected shortcode injections, specifically looking for the '[mb_user_profile_register]' shortcode in posts modified after the plugin update threshold.


Immediate actions

Upgrade Meta Box AIO, Meta Box Frontend Submission, and Meta Box User Profile to versions post-dating 3.11.0 and 4.5.6.

IT Operations 24h

Threat Hunt

Search WordPress post content for the presence of the [mb_user_profile_register] shortcode in public or sensitive pages.

T1068 high high confidence hunt now

Data: WordPress database table (wp_posts)

Mitigations

Patch Meta Box plugin suite to the latest vendor-provided versions.

immediate IT Operations

CVE-2026-13355