Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.2
Meta Box Plugin for WordPress: Attackers Can Delete Server Files
CVE-2025-14675
GHSA-m4q3-832v-44j6
GHSA-m4q3-832v-44j6
Summary
The Meta Box plugin for WordPress allows attackers with contributor access to delete any file on the server, potentially leading to critical security risks. This affects all versions of the plugin up to and including 5.11.1. Update to the latest version to fix this issue.
What to do
- Update wpmetabox meta-box to version 5.11.2.
- Update wpmetabox wpmetabox/meta-box to version 5.11.2.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| wpmetabox | meta-box | <= 5.11.2 | 5.11.2 |
| wpmetabox | wpmetabox/meta-box | <= 5.11.2 | 5.11.2 |
Original title
Meta Box Plugin for WordPress: Authenticated (Contributor+) Arbitrary File Deletion via ajax_delete_file
Original description
The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
nvd CVSS3.1
7.2
Vulnerability type
CWE-22
Path Traversal
- https://github.com/wpmetabox/meta-box/pull/1654
- https://plugins.trac.wordpress.org/browser/meta-box/tags/5.11.0/inc/fields/file....
- https://plugins.trac.wordpress.org/browser/meta-box/tags/5.11.0/inc/fields/file....
- https://plugins.trac.wordpress.org/changeset/3475210/meta-box#file3
- https://www.wordfence.com/threat-intel/vulnerabilities/id/036467de-95bb-4bfd-952...
- https://nvd.nist.gov/vuln/detail/CVE-2025-14675
- https://github.com/wpmetabox/meta-box/commit/08c6511607b9cc9fe8d0de7a7e91c9d5d41...
- https://github.com/advisories/GHSA-m4q3-832v-44j6
- https://github.com/wpmetabox/meta-box Product
Published: 7 Mar 2026 · Updated: 13 Mar 2026 · First seen: 7 Mar 2026