CVE-2026-39468PoC

LOWCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-27); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-27: 1Mentions · 2026-07-29: 1PoC Mentioned / Linked · 2026-04-27: 1Exploit Tool / Code · 2026-04-27: 1Technical Details · 2026-04-27: 1Technical Details · 2026-07-29: 104-2707-29
Signal classification2 categories
PoC
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-271
PoC1
2026-07-291
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-39468 - high 🚨 Meta Box &lt;= 5.11.1 - Arbitrary File Deletion &gt; The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to ins... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-39468 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the CVE-2026-39468 vulnerability in Meta Box, detailing affected versions and the arbitrary file deletion flaw without providing evidence of exploitation or remediation.

    00001224
    1.1K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-39468-meta-box-version-5-11-1-high-vulnerability-proof-of-concept CVE-2026-39468 meta-box (CVSS Score 8.1) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A proof‑of‑concept for CVE‑2026‑39468 in the WordPress Meta‑Box plugin is shared on AtomiceEdge, including the CVSS score and plugin version, but no evidence of active exploitation, patch, or mitigation is mentioned.

    0000046
    6 followersView on X

Explore more