POCBIT

CVE-2026-13355 — Meta Box AIO ≤ 3.11.0 Unauthenticated Admin Privilege Escalation

Chained unauthenticated privilege escalation to **administrator** in Meta Box AIO (≤ 3.11.0) involving **MB Frontend Submission** (≤ 4.5.6) frontend submission logic.

#wordpress#meta-box#privilege-escalation#unauthenticated

CVE:

CVE-2026-13355

Date:

2026-09-25

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-13355 is a chained issue in the Meta Box All-in-One bundle (≤ 3.11.0), including MB Frontend Submission ≤ 4.5.6. Attackers without accounts may abuse frontend submission flows to escalate to WordPress administrator.

Impact

Full site takeover: plugin installation, user management, backdoors, and data theft.

Affected software

  • Meta Box AIO ≤ 3.11.0
  • MB Frontend Submission ≤ 4.5.6 (component called out in research)

Remediation

Update Meta Box packages through official channels immediately on any site using frontend submission features.

Legal and ethical use

Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.

References

  • Look up the CVE ID on NVD and the CVE Program for official records.
  • Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.