{"id":"CVE-2025-14675","aliases":["GHSA-m4q3-832v-44j6"],"url":"https://o3.security/vulnerability/CVE-2025-14675","summary":"Meta Box <= 5.11.1 - Authenticated (Contributor+) Arbitrary File Deletion","details":"The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).","published":"2026-03-07T07:22:02.665Z","modified":"2026-07-15T01:48:51.132818615Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"wpmetabox/meta-box","fixedVersion":"5.11.2"}],"fix":{"url":"https://github.com/wpmetabox/meta-box/pull/1654","label":"wpmetabox/meta-box#1654"},"references":[{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/meta-box/tags/5.11.0/inc/fields/file.php#L30"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/browser/meta-box/tags/5.11.0/inc/fields/file.php#L54"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset/3475210/meta-box#file3"},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/036467de-95bb-4bfd-9522-df8dc17f3102?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14675.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14675"},{"type":"FIX","url":"https://github.com/wpmetabox/meta-box/pull/1654"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:51.132818615Z"}}