Junglewise Threat Intelligence

CVE-2026-8422: WordPress Remove meta boxes per user role CSRF in settings page

CVE-2026-8422 · Severity: medium · CVSS 4.3 · Published 2026-06-02

Vendors: Wordpress.

Executive brief

The 'Remove meta boxes per user role' plugin for WordPress, which allows administrators to hide specific interface elements from different user groups, is vulnerable to a security flaw. An attacker could trick a site administrator into clicking a malicious link, allowing the attacker to change or reset the plugin's settings. This could lead to unauthorized changes in what different users can see or interact with on the website's dashboard.

Technical details

The 'Remove meta boxes per user role' plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to and including 1.01. The vulnerability stems from missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' settings page. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link, while authenticated to the WordPress dashboard. Successful exploitation allows the attacker to modify or reset the plugin's configuration regarding per-role meta box visibility. At the time of the advisory, the vulnerability affects all versions up to 1.01.

Affected products

  • WordPress Remove meta boxes per user role up to, and including, 1.01

Timeline

  • 2026-06-02: advisory: NVD publication date

References