<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Meta Box AIO (&lt;= 3.11.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/meta-box-aio--3.11.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 06:33:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/meta-box-aio--3.11.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Privilege Escalation in Meta Box AIO for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-09-meta-box-privilege-escalation/</link><pubDate>Tue, 22 Sep 2026 06:33:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-meta-box-privilege-escalation/</guid><description>An unauthenticated privilege escalation vulnerability (CVE-2026-13355) in the Meta Box AIO plugin allows attackers to overwrite post content with arbitrary shortcodes to register administrative accounts.</description><content:encoded><![CDATA[<p>The Meta Box AIO plugin for WordPress, along with its standalone components Meta Box Frontend Submission and Meta Box User Profile, is affected by a critical vulnerability (CVE-2026-13355) that enables unauthenticated privilege escalation to the Administrator role. The vulnerability exists due to a chained flaw between the mb-frontend-submission and mb-user-profile components.</p>
<p>An attacker can exploit the 'populate_via_query_string()' function, which improperly processes the 'rwmb_frontend_field_object_id' GET parameter without authorization checks. This allows the attacker to overwrite the content of any post on the target WordPress site using 'wp_update_post()'. By injecting a malicious '[mb_user_profile_register]' shortcode into a post, the attacker leverages the mb-user-profile component's failure to validate the 'role' and 'auto_login' shortcode attributes. This process permits the registration or modification of user accounts, granting the attacker administrative access to the WordPress environment. This vulnerability affects Meta Box AIO versions up to 3.11.0, Meta Box Frontend Submission up to 4.5.6, and Meta Box User Profile up to 3.11.0.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain full administrative control over the affected WordPress installation. This can lead to unauthorized access to sensitive site data, modification of content, installation of malicious plugins or themes, and potential lateral movement into the hosting infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate update of the Meta Box AIO plugin, Meta Box Frontend Submission, and Meta Box User Profile to the latest patched versions released by the vendor. Conduct a forensic audit of posts and pages for unexpected shortcode injections, specifically looking for the '[mb_user_profile_register]' shortcode in posts modified after the plugin update threshold.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>