Metabox develops a WordPress plugin for custom post types and metadata management that operates within the content-management ecosystem. The plugin's vulnerability profile centers on application-layer input-handling weaknesses, including cross-site scripting and authorization gaps, which are characteristic of extensions operating in a user-facing, post-editing context. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Metabox over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14675HIGH The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and in | Mar 7, 2026 | 7.2 | 25 | NO | NO |
CVE-2019-14794HIGH The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders. | Aug 9, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-14793MEDIUM The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter. | Aug 9, 2019 | 6.5 | 22 | NO | NO |
CVE-2024-1204MEDIUM The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts. | Apr 15, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-6526MEDIUM The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta values displayed through the plugin's shortc | Feb 5, 2024 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Metabox.
Media articles that mention a CVE ID that affects a product developed by Metabox — matched by CVE ID, not by vendor name.