Ghostwire

CVE-2026-15248: The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment...

MEDIUM CVSS 0.0

Published: August 2, 2026 | Last Modified: August 2, 2026

Description

The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References