No analysis available yet.
Vendor Solution
Update the WordPress Meta Box – WordPress Custom Fields Framework Plugin to the latest available version (at least 5.11.2).
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 16 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions. | |
| Title | WordPress Meta Box – WordPress Custom Fields Framework plugin <= 5.11.1 - Arbitrary File Deletion vulnerability | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-06-16T14:24:05.282Z
Reserved: 2026-04-07T10:41:57.169Z
Link: CVE-2026-39468
Updated: 2026-06-16T14:24:00.810Z
Status : Deferred
Published: 2026-06-15T21:16:43.607
Modified: 2026-06-15T21:24:32.790
Link: CVE-2026-39468
No data.
OpenCVE Enrichment
No data.
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')