Executive brief
The Meta Box AIO plugin for WordPress, which provides advanced custom field and frontend submission capabilities, contains a security flaw that allows unauthorized users to delete content. An unauthenticated attacker can exploit this to delete any post or page on the website by sending a specifically crafted request. This could lead to significant data loss and disruption of website operations.
Technical details
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization in the MB Frontend Submission extension (up to version 3.8.0). The vulnerability exists within the handle_request() function, which routes the 'mbfs_delete' action without verifying user capabilities or post ownership. Additionally, the nonce verification in check_ajax() is bypassed because it is gated behind an is_ajax() check, which returns false for template_redirect requests. An unauthenticated attacker can exploit this by providing a target post ID via the 'rwmb_frontend_field_object_id' GET parameter on any page hosting a frontend submission form. This allows for the deletion of arbitrary posts and pages regardless of whether the 'allow_delete' setting is enabled. The issue was addressed in version 3.9.0.
Affected products
- Meta Box Meta Box AIO <= 3.8.0
Timeline
- 2026-07-17: patched: Fixed in version 3.9.0
- 2026-07-29: disclosed: CVE published by Wordfence/NVD