Known CVE
Meta Box <= 5.11.1 - Arbitrary File Deletion
The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_delete_file function. This makes it possible for authenticated attackers with Contributor-level access and above to delete arbitrary files on the server.
CVE-2026-39468
High2026CVSS 7.2CWE-22
cve2026 · wordpress · wp · wp-plugin · meta-box · file-deletion · passive
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website