CMB2 <= 2.13.2 - Authenticated (Editor+) Limited Options Update via REST API 'object_type' and 'object_id' Parameters
- ID
- WPSEC-2026-0552
- Plugin
- CMB2 (cmb2)
- Affected
- from 2.2.3 before 2.13.3
- Remediation
- Update to 2.13.3 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- CMB2 on WPSec AttackSurface
- Fix released
- Published
Description
The CMB2 plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.2.3 up to, and including, 2.13.2. This is due to the REST API boxes/fields endpoints applying the user-supplied 'object_type' and 'object_id' parameters to a box without checking them against the object types and option keys the box is registered for. On sites where a plugin or theme registers a CMB2 box with REST API write access, authenticated attackers with editor-level access and above can write or delete the box's field values on object types the box was not registered for, including any entry in the wp_options table, which can corrupt core settings and make the site inaccessible. Through the same parameters, values stored under a REST-readable field's ID on other objects and options can also be read. The minimum role depends on the box's permission callbacks and defaults to users with the edit_others_posts capability.
References
- https://wpsec.com/vuln/WPSEC-2026-0552/
- https://plugins.svn.wordpress.org/cmb2/tags/2.13.3/
- https://wordpress.org/plugins/cmb2/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS