CVE-2026-13355 is an unauthenticated privilege-escalation vulnerability in Meta Box AIO for WordPress through version 3.11.0. The flaw chains an authorization bypass in the mb-frontend-submission component with insufficient validation in the mb-user-profile component. A GET parameter can override a frontend form's target object identifier without authorization, while form processing does not enforce the edit-permission check used during rendering. An attacker can consequently overwrite arbitrary WordPress page content with a crafted user-registration shortcode. The user-profile functionality accepts attacker-controlled role and automatic-login attributes without validating the requested role, enabling creation of an Administrator account. The standalone Meta Box Frontend Submission plugin through 4.5.6 and Meta Box User Profile plugin through 3.11.0 are also affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file Python repository implements a standalone scanner and exploitation utility for the claimed CVE-2026-13355 privilege-escalation chain in WordPress Meta Box components. Its main entry point, poc.py, uses requests/urllib3 with TLS verification disabled, supports a single target or concurrent target lists, probes publicly exposed plugin files for component/version evidence, crawls common site paths for MB Frontend Submission form markers, and writes JSONL/hit/candidate output files. The exploit chain abuses rwmb_frontend_field_object_id to target an arbitrary post or page through a public mbfs form, submits poisoned post_content containing an administrator registration shortcode, and can verify access via WordPress login/admin paths. fofa_to_list.py is a separate helper that normalizes FOFA CSV exports into deduplicated HTTP(S) target lists; it does not exploit targets itself. The repository includes dependencies and a sample target list, but no external framework integration. The provided material is coherent exploit code rather than a detection-only script; successful exploitation creates a configurable or generated administrator account, although practical success depends on an exposed writable mbfs form, a valid object ID, lack of content filtering, and vulnerable plugin behavior.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical (CVSS 9.8) unauthenticated privilege-escalation chain in Meta Box AIO and its Meta Box Frontend Submission and Meta Box User Profile components. The chain combines an unchecked object_id override, a missing permission check in Form::process(), and unvalidated shortcode role and auto_login attributes to enable full WordPress administrator takeover.
An unauthenticated privilege-escalation-to-administrator vulnerability caused by a chained authorization failure in Meta Box AIO. Attackers can alter arbitrary WordPress page content through the frontend-submission component, inject an mb_user_profile_register shortcode, and abuse unvalidated role and auto-login attributes to obtain Administrator privileges. Standalone Meta Box Frontend Submission and Meta Box User Profile plugins are also affected.
A critical unauthenticated privilege-escalation vulnerability caused by chained authorization and input-validation flaws in Meta Box AIO's frontend-submission and user-profile components. An attacker can modify page content to inject an mb_user_profile_register shortcode with attacker-controlled role and auto-login attributes, creating or elevating an account to Administrator.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.