Vulnerabilities / CMB2 / WPSEC-2026-0552

CMB2 <= 2.13.2 - Authenticated (Editor+) Limited Options Update via REST API 'object_type' and 'object_id' Parameters

Medium 5.0 CWE-639Fixed in 2.13.3
ID
WPSEC-2026-0552
Plugin
CMB2 (cmb2)
Affected
from 2.2.3 before 2.13.3
Remediation
Update to 2.13.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Weakness
CWE-639
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
CMB2 on WPSec AttackSurface
Fix released
Published

Description

The CMB2 plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.2.3 up to, and including, 2.13.2. This is due to the REST API boxes/fields endpoints applying the user-supplied 'object_type' and 'object_id' parameters to a box without checking them against the object types and option keys the box is registered for. On sites where a plugin or theme registers a CMB2 box with REST API write access, authenticated attackers with editor-level access and above can write or delete the box's field values on object types the box was not registered for, including any entry in the wp_options table, which can corrupt core settings and make the site inaccessible. Through the same parameters, values stored under a REST-readable field's ID on other objects and options can also be read. The minimum role depends on the box's permission callbacks and defaults to users with the edit_others_posts capability.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0