The Meta Box AIO WordPress plugin is vulnerable to missing authorization (CVE-2026-14488, CVSS 9.1) in versions up to 3.8.0, allowing unauthenticated attackers to delete arbitrary posts and pages via a bypassable nonce check. The flaw impacts any site with a frontend submission form regardless of delete settings.

The plugin's nonce check inside check_ajax() sits behind an is_ajax() guard that evaluates to false during template_redirect calls, allowing the verification to be bypassed.
Exploitation succeeds regardless of whether the allow_delete setting is active.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
A Bloomberg report citing anonymous sources claims that disappointing commercial performance of Kojima’s prior Death Stranding titles, missed deadlines, ballooning costs, and limited exclusivity led PlayStation to cancel Physint. Xbox will now partner with the developer on the project.
Tesla has started sending invitations for its Semi Rollout event on September 24 at the new factory in Sparks, Nevada. The gathering will showcase the 1.7 million-square-foot facility built to produce up to 50,000 trucks per year along with refreshed vehicle features and fleet economics.
Anthropic thwarted unidentified actors seeking to use its Claude model for gain-of-function research on the chikungunya virus that could support bioweapon development. The firm issued its latest misuse report, following earlier ones in March, August, and November 2025, warning that advancing AI capabilities heighten risks unless developers and governments collaborate on stronger defenses.