
CVE-2026-15248 The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-… https://www.cve.org/CVERecord?id=CVE-2026-15248
Post summary
The message announces a privilege‑escalation vulnerability in the Meta Box WordPress plugin, detailing an authorization check failure without mentioning any PoC, exploit code, or patch. It is a straightforward disclosure of a new vulnerability.

