Executive brief
Meta Box is a popular WordPress plugin used by developers to create custom data fields and metadata for websites. A security flaw in this plugin allows users with 'Contributor' level access to delete arbitrary files from the web server. This could lead to a complete website failure or the removal of critical configuration files, potentially disrupting business operations and requiring manual restoration from backups.
Technical details
The Meta Box plugin for WordPress (versions up to and including 5.11.1) is vulnerable to arbitrary file deletion. This issue stems from a path traversal vulnerability (CWE-22) where the application fails to properly sanitize user-supplied input used to identify files for deletion. An attacker with Contributor-level privileges can exploit this to delete sensitive files outside of the intended directory, such as wp-config.php or .htaccess, potentially leading to a Denial of Service (DoS) or site takeover. The vulnerability is addressed in version 5.11.2.
Affected products
- eLightUp Meta Box – WordPress Custom Fields Framework <= 5.11.1
Timeline
- 2026-01-27: other: Vulnerability reported by Nguyen Ba Khanh
- 2026-04-13: advisory: Initial advisory published by Patchstack
- 2026-04-13: patched: Version 5.11.2 released to address the issue
- 2026-06-15: disclosed: CVE published to NVD