UNKNOWN (0.0)
    Plugin

    Arbitrary File Deletion in Meta Box Plugin for WordPress

    Published Date: 3/7/2026
    CVE ID: CVE-2025-14675

    Summary

    The Meta Box plugin for WordPress contains a vulnerability in its 'ajax_delete_file' function that allows authenticated users to delete any file on the server. This issue, affecting versions up to 5.11.1, can lead to severe consequences, such as remote code execution, if critical files are deleted.

    Vulnerability Details

    The vulnerability in the Meta Box plugin arises from improper validation of file paths within the 'ajax_delete_file' function. This lack of validation allows attackers with Contributor-level permissions or higher to exploit the plugin by crafting requests that result in the deletion of files on the server. The critical risk involved with this vulnerability is the potential deletion of essential WordPress configuration files, such as wp-config.php, which can lead to downtime or allow attackers to execute remote code. This exposure emphasizes the need for robust access control and file path validation mechanisms to prevent unauthorized file manipulations. The threat is particularly concerning due to the plugin's widespread usage across numerous WordPress installations. Therefore, addressing this vulnerability is crucial for maintaining site integrity and security.

    Recommendations

    To mitigate this vulnerability, site administrators should restrict plugin access to only necessary user roles and limit file system permissions to minimize damage from unauthorized deletions. Implementing application-level firewalls and monitoring for unusual file deletion activity can provide additional layers of security. It's also advisable to keep regular backups of critical files to restore them if unauthorized deletion occurs.

    Available Fixes

    Last Updated: 3/10/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More