The Meta Box AIO WordPress plugin is vulnerable to missing authorization (CVE-2026-14488, CVSS 9.1) in versions up to 3.8.0, allowing unauthenticated attackers to delete arbitrary posts and pages via a bypassable nonce check. The flaw impacts any site with a frontend submission form regardless of delete settings.

The plugin's nonce check inside check_ajax() sits behind an is_ajax() guard that evaluates to false during template_redirect calls, allowing the verification to be bypassed.
Exploitation succeeds regardless of whether the allow_delete setting is active.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Bloomberg's Mark Gurman reports that Apple intends to introduce a brand-new smart home hub sometime from October through the first months of next year. The unit will feature an approximately 7-inch screen, Siri AI at its center, facial recognition, adaptive interface scaling, and a range of smart-home tools in both tabletop and wall-mounted editions.
Medical Computer Business Services disclosed a 2025 network breach that exposed the sensitive information of 1,261,464 people. The incident highlights risks to healthcare data aggregators that process patient records for multiple providers.
Microsoft disclosed CVE-2026-57990, a high-severity vulnerability in Chromium-based Edge that lets unauthorized attackers disclose information by accessing external files or directories over a network. The CVSS 7.4 flaw, published July 26 2026, underscores the need for prompt patching in widely deployed browsers.