{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/meta-box-frontend-submission--4.5.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-13355"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=1AEB15AD-540E-553B-89AA-F0854ADA2F6E\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Meta Box AIO (\u003c= 3.11.0)","Meta Box Frontend Submission (\u003c= 4.5.6)","Meta Box User Profile (\u003c= 3.11.0)","MB Frontend Submission (\u003c= 4.5.6)","MB User Profile (\u003c= 3.11.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Meta Box"],"content_html":"\u003cp\u003eThe Meta Box AIO plugin for WordPress, along with its standalone components Meta Box Frontend Submission and Meta Box User Profile, is affected by a critical vulnerability (CVE-2026-13355) that enables unauthenticated privilege escalation to the Administrator role. The vulnerability exists due to a chained flaw between the mb-frontend-submission and mb-user-profile components.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit the 'populate_via_query_string()' function, which improperly processes the 'rwmb_frontend_field_object_id' GET parameter without authorization checks. This allows the attacker to overwrite the content of any post on the target WordPress site using 'wp_update_post()'. By injecting a malicious '[mb_user_profile_register]' shortcode into a post, the attacker leverages the mb-user-profile component's failure to validate the 'role' and 'auto_login' shortcode attributes. This process permits the registration or modification of user accounts, granting the attacker administrative access to the WordPress environment. This vulnerability affects Meta Box AIO versions up to 3.11.0, Meta Box Frontend Submission up to 4.5.6, and Meta Box User Profile up to 3.11.0.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain full administrative control over the affected WordPress installation. This can lead to unauthorized access to sensitive site data, modification of content, installation of malicious plugins or themes, and potential lateral movement into the hosting infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update of the Meta Box AIO plugin, Meta Box Frontend Submission, and Meta Box User Profile to the latest patched versions released by the vendor. Conduct a forensic audit of posts and pages for unexpected shortcode injections, specifically looking for the '[mb_user_profile_register]' shortcode in posts modified after the plugin update threshold.\u003c/p\u003e\n","date_modified":"2026-09-22T07:38:12Z","date_published":"2026-09-22T06:33:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-meta-box-privilege-escalation/","summary":"An unauthenticated privilege escalation vulnerability (CVE-2026-13355) in the Meta Box AIO plugin allows attackers to overwrite post content with arbitrary shortcodes to register administrative accounts.","title":"Unauthenticated Privilege Escalation in Meta Box AIO for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-meta-box-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Meta Box Frontend Submission (\u003c= 4.5.6)","version":"https://jsonfeed.org/version/1.1"}