Executive brief
Meta Box AIO is a WordPress plugin that lets developers and administrators build custom content management forms. An unauthenticated attacker can exploit a chain of validation flaws to inject a malicious shortcode into any page, then use that shortcode to elevate themselves to Administrator with full site control, allowing complete site takeover and data exfiltration.
Technical details
The vulnerability chains two authorization flaws: the mb-frontend-submission component's populate_via_query_string() function fails to validate the rwmb_frontend_field_object_id GET parameter before overwriting post_id, and Form::process() lacks the user_can_edit() check present in render(), allowing unauthenticated attackers to inject arbitrary shortcodes via wp_update_post(). The mb-user-profile component then directly trusts role and auto_login attributes in [mb_user_profile_register] shortcode without validation, enabling privilege escalation. No user interaction is required beyond network access.
Affected products
- Meta Box Meta Box AIO up to 3.11.0
- Meta Box Meta Box Frontend Submission up to 4.5.6
- Meta Box Meta Box User Profile up to 3.11.0
Timeline
- 2026-09-22: disclosed