Skip to finding
important · Privilege escalation

An unauthenticated Meta Box frontend-form caller can rewrite page content and create a WordPress administrator.

Affects

Meta Box AIO and the standalone Meta Box Frontend Submission and Meta Box User Profile extensions for WordPress sites.

On sites exposing the affected optional components, an attacker-selected object ID reaches form processing without the render-time authorization check. The attacker can replace page content with a registration shortcode that selects the administrator role and automatic login. Meta Box AIO is fixed, but fixed standalone-extension versions were not established.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 22, 2026