S4E just found a high [ai] pa ssl inspection control
high·Product Based Web Vulnerabilities·Updated Jul 29, 2026

CVE-2025-14675 Scanner

CVE-2025-14675 Scanner - Arbitrary File Deletion vulnerability in Meta Box

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-39468
6.8
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Meta Box – WordPress Custom Fields Frameworkby eLightUp
n/a
Updated Aug 5, 2026View on NVD →
Detail

The Meta Box plugin is a widely used tool for WordPress users looking to add custom fields and meta boxes to their websites without extensive programming knowledge. It's utilized by site administrators and developers alike to enhance the functionality and user interface of their WordPress sites. Meta Box allows for customization to meet the needs of various types of content, from simple blogs to complex e-commerce sites. The plugin offers a diverse set of features, supporting different types of meta fields, which makes it versatile for many applications. Its integration with WordPress ensures a seamless addition to the website's self-contained ecosystem. Users primarily include WordPress enthusiasts and professional web developers looking for an easy, yet powerful tool to manage custom data.

Arbitrary file deletion vulnerabilities occur when unauthorized users can delete files on a server, that they would typically not have permissions to do so. This specific vulnerability in Meta Box allows authenticated users with Contributor-level access to delete files, due to improper validation of file paths. Such vulnerabilities can lead to secondary exploits if critical files are deleted, causing potential site disruption or unauthorized access. In the context of WordPress, where a file like wp-config.php is crucial, the ramifications can be significant. An arbitrary file deletion vulnerability may allow attackers to interfere with normal operations, leading to potential system outages or data loss. Vulnerability exploitation can adversely impact server integrity and ongoing security.

The vulnerability resides within the ajax_delete_file function of the Meta Box plugin, which fails to properly validate file paths before performing deletion operations. This oversight makes it possible to manipulate file paths to remove unintended files from the server's filesystem. By submitting specially crafted requests, authenticated users with appropriate roles (e.g., Contributors) can remove critical WordPress files. The vulnerable endpoint is believed to be accessed over traditional HTTP methods, where attackers can input malicious file paths. The failure to adequately sanitize input in this function directly exposes the server to elevated risk from file deletion attacks. The underlying technical flaw is linked to an insufficient validation procedure, according to CWE-22.

If exploited, this vulnerability could allow a Malicious user to delete any file on the server where the Meta Box plugin is installed. Such actions could potentially result in the deletion of critical files necessary for the server and service operation, such as configuration files. It could further lead to Denial of Service attacks by making the website inoperable, and introduce security backdoors if vital system files are removed, leading to remote code execution. Consequences include diminished site reliability and potential breach of secure data if security files are targeted and removed. Ultimately, such exploitation undermines trust with users and can incur data recovery costs.

REFERENCES

Solution Advice
  • Update Meta Box to version 5.11.2 or later.
  • Restrict contributor-level access to necessary users only.
  • Disallow file operations to users outside of necessary administrative roles.
  • Regularly audit plugin security and apply updates promptly.
  • Monitor server logs for unauthorized file operations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.