{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/meta-box-aio-plugin--3.8.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-14488"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Meta Box AIO plugin (\u003c= 3.8.0)","MB Frontend Submission extension (\u003c= 3.8.0)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","missing-authorization","web-application","plugin-vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["Meta Box","WordPress"],"content_html":"\u003cp\u003eA critical Missing Authorization vulnerability, tracked as CVE-2026-14488, has been identified in the Meta Box AIO plugin for WordPress, specifically within its MB Frontend Submission extension, affecting all versions up to and including 3.8.0. This flaw allows unauthenticated attackers to delete any post or page on a vulnerable WordPress site. The vulnerability arises because the plugin's \u003ccode\u003ehandle_request()\u003c/code\u003e function, when routed through the \u003ccode\u003etemplate_redirect\u003c/code\u003e dispatcher, processes the \u003ccode\u003embfs_delete\u003c/code\u003e action without proper capability or ownership checks. Furthermore, nonce verification, typically handled by \u003ccode\u003echeck_ajax()\u003c/code\u003e, is bypassed because \u003ccode\u003eis_ajax()\u003c/code\u003e returns false for \u003ccode\u003etemplate_redirect\u003c/code\u003e requests. This oversight permits attackers to specify an arbitrary post ID via the \u003ccode\u003erwmb_frontend_field_object_id\u003c/code\u003e GET parameter on any page hosting a frontend submission form, regardless of whether the \u003ccode\u003eallow_delete\u003c/code\u003e option is enabled, leading to unauthorized data destruction.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress site running the Meta Box AIO plugin with the MB Frontend Submission extension, version 3.8.0 or older.\u003c/li\u003e\n\u003cli\u003eThe attacker browses the target WordPress site to locate any public-facing page that hosts a frontend submission form.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP GET request targeting this identified page.\u003c/li\u003e\n\u003cli\u003eThe request includes the \u003ccode\u003erwmb_frontend_field_object_id\u003c/code\u003e GET parameter, supplying the ID of an arbitrary post or page the attacker intends to delete. For example, \u003ccode\u003eGET /submission-page/?rwmb_frontend_field_object_id=123\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe WordPress application processes the incoming request, and the vulnerable \u003ccode\u003etemplate_redirect\u003c/code\u003e dispatcher invokes the plugin's \u003ccode\u003ehandle_request()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ehandle_request()\u003c/code\u003e function, due to the missing authorization checks and bypassed nonce verification, proceeds to route and execute the \u003ccode\u003embfs_delete\u003c/code\u003e action.\u003c/li\u003e\n\u003cli\u003eThe post or page corresponding to the ID provided in the \u003ccode\u003erwmb_frontend_field_object_id\u003c/code\u003e parameter is then deleted from the WordPress site's database.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-14488 results in significant data loss and service disruption for affected WordPress sites. Unauthenticated attackers can delete any posts, pages, or custom post types, leading to the removal of critical content, defacement, or rendering the website unusable. This can severely damage an organization's reputation, cause financial losses due to lost data or operational downtime, and necessitate extensive recovery efforts. The CVSS v3.1 Base Score for this vulnerability is 9.1, indicating critical severity and ease of exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-14488 by updating the Meta Box AIO plugin to a version greater than 3.8.0 immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect CVE-2026-14488 Exploitation - Meta Box AIO Plugin Missing Authorization\u0026quot; to your SIEM for web server logs.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for \u003ccode\u003ecs-uri-query\u003c/code\u003e containing \u003ccode\u003erwmb_frontend_field_object_id=\u003c/code\u003e for suspicious activity prior to patching.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T11:18:26Z","date_published":"2026-07-29T11:18:26Z","id":"https://feed.craftedsignal.io/briefs/2026-07-meta-box-aio-cve-2026-14488/","summary":"Unauthenticated attackers can exploit a Missing Authorization vulnerability (CVE-2026-14488) in the MB Frontend Submission extension of the Meta Box AIO plugin for WordPress, affecting versions up to 3.8.0, to delete arbitrary posts and pages by injecting a crafted post ID via a GET parameter.","title":"Meta Box AIO Plugin Vulnerable to Unauthenticated Post Deletion via CVE-2026-14488","url":"https://feed.craftedsignal.io/briefs/2026-07-meta-box-aio-cve-2026-14488/"}],"language":"en","title":"CraftedSignal Threat Feed - Meta Box AIO Plugin (\u003c= 3.8.0)","version":"https://jsonfeed.org/version/1.1"}