Skip to content

Known CVE

Meta Box <= 5.11.1 - Arbitrary File Deletion

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_delete_file function. This makes it possible for authenticated attackers with Contributor-level access and above to delete arbitrary files on the server.

CVE-2026-39468

High2026CVSS 7.2CWE-22

cve2026 · wordpress · wp · wp-plugin · meta-box · file-deletion · passive

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website