CVE-2026-13355 — Meta Box AIO ≤ 3.11.0 Unauthenticated Admin Privilege Escalation
Chained unauthenticated privilege escalation to **administrator** in Meta Box AIO (≤ 3.11.0) involving **MB Frontend Submission** (≤ 4.5.6) frontend submission logic.
#wordpress#meta-box#privilege-escalation#unauthenticated
Description
Overview
CVE-2026-13355 is a chained issue in the Meta Box All-in-One bundle (≤ 3.11.0), including MB Frontend Submission ≤ 4.5.6. Attackers without accounts may abuse frontend submission flows to escalate to WordPress administrator.
Impact
Full site takeover: plugin installation, user management, backdoors, and data theft.
Affected software
- Meta Box AIO ≤ 3.11.0
- MB Frontend Submission ≤ 4.5.6 (component called out in research)
Remediation
Update Meta Box packages through official channels immediately on any site using frontend submission features.
Legal and ethical use
Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.
References
- Look up the CVE ID on NVD and the CVE Program for official records.
- Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.