CVE-2026-13355

LOWCVSS 9.8 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::process() lacks the user_can_edit() check present in render(), allowing unauthenticated attackers to overwrite the post_content of any page with an arbitrary shortcode via wp_update_post(); the mb-user-profile component then directly trusts the 'role' and 'auto_login' shortcode attributes in the injected [mb_user_profile_register] shortcode with no role validation. This makes it possible for unauthenticated attackers to elevate their privileges to Administrator. The standalone plugins Meta Box Frontend Submission (in versions up to 4.5.6) and Meta Box User Profile (versions up to 3.11.0) are also affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-09-22: 509-22
Referenced assets5 URLs
Full discourse5 posts
  • mürrez@murrezsec

    CVE-2026-13355 (CVSS 9.8) — Meta Box AIO ≤3.11.0 unauth admin chain: MB Frontend Submission post_content overwrite + mb_user_profile_register role=administrator PoC: check/exploit, mass scan w/ mbfs vs mbup-only detection https://github.com/murrez/CVE-2026-13355 #CVE #WordPress #Infosec

    0001038
    602 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Meta Box AIO Unauth Admin PrivEsc via object_id Override + Shortcode Chain (CVE-2026-13355) Meta Box AIO for WordPress lets attackers override rwmb_frontend_field_object_id to target arbitrary object_id; missing auth checks allow overwriting page content with a crafted shortcode that makes the User Profile component trust role and auto_login attributes, enabling unauthenticated admin registration/login. Sites not using Frontend Submission/User Profile shortcodes aren’t exposed. 👉Affected: Meta Box AIO <= 3.11.0; Meta Box Frontend Submission <= 4.5.6; Meta Box User Profile <= 3.11.0

    0000027
    304 followersView on X
  • ThreatAft@ThreatAft

    🚨 META BOX AIO CVE-2026-13355 — CVSS 9.8 Unauthenticated → Administrator. Three flaws chained: • Unchecked object_id • Missing permission check • Unvalidated role attribute PATCH NOW. → https://threataft.com/articles/meta-box-aio-cve-2026-13355-unauthenticated-privilege-escalation #MetaBox #WordPress #PatchNow #CyberSecurity #ThreatIntel

    0000026
    43 followersView on X
  • cybrmonk@cybr_monk

    CVE-2026-13355 Lets Unauthenticated Users Grab WordPress Admin Rights in Minutes https://cybrmonk.com/blog/cve-2026-13355-lets-unauthenticated-users-grab-wordpress-admin-rights-in-minutes #cybersecurity #threatintelligence https://t.co/q7YZPg6rRh

    0000022
    47 followersView on X
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-13355 PT ID: PT-2026-96644 Vendor: WordPress / Meta Box Product: Meta Box Frontend Submission Description: The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::process() lacks the user_can_edit() check present in render(), allowing unauthenticated attackers to overwrite the post_content of any page with an arbitrary shortcode via wp_update_post(); the mb-user-profile component then directly trusts the 'role' and 'auto_login' shortcode attributes in the injected [mb_user_profile_register] shortcode with no role validation. This makes it possible for unauthenticated attackers to elevate their privileges to Administrator. The standalone plugins Meta Box Frontend Submission (in versions up to 4.5.6) and Meta Box User Profile (versions up to 3.11.0) are also affected. References: • https://dbu.gs/vulnerability/PT-2026-96644 • https://github.com/murrez/cve-2026-13355

    00000224
    3.5K followersView on X

Explore more