{
 "id": "WPSEC-2026-0552",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0552/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0552/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0552/index.md",
 "title": "CMB2 <= 2.13.2 - Authenticated (Editor+) Limited Options Update via REST API 'object_type' and 'object_id' Parameters",
 "description": "The CMB2 plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.2.3 up to, and including, 2.13.2. This is due to the REST API boxes/fields endpoints applying the user-supplied 'object_type' and 'object_id' parameters to a box without checking them against the object types and option keys the box is registered for. On sites where a plugin or theme registers a CMB2 box with REST API write access, authenticated attackers with editor-level access and above can write or delete the box's field values on object types the box was not registered for, including any entry in the wp_options table, which can corrupt core settings and make the site inaccessible. Through the same parameters, values stored under a REST-readable field's ID on other objects and options can also be read. The minimum role depends on the box's permission callbacks and defaults to users with the edit_others_posts capability.",
 "plugin": {
  "slug": "cmb2",
  "name": "CMB2",
  "full_name": "CMB2",
  "wordpress_org": "https://wordpress.org/plugins/cmb2/",
  "advisories_url": "https://wpsec.com/vuln/plugin/cmb2/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/cmb2"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.0,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.2.3",
    "from_inclusive": true,
    "to": "2.13.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.2.3 before 2.13.3"
  ]
 },
 "introduced_in": "2.2.3",
 "fixed_in": "2.13.3",
 "remediation": "Update to 2.13.3 or later.",
 "fix_released": "2026-10-03T19:04:37+00:00",
 "published": "2026-10-07T14:47:02+00:00",
 "updated": "2026-10-07T13:54:58.211999+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0552/",
  "https://plugins.svn.wordpress.org/cmb2/tags/2.13.3/",
  "https://wordpress.org/plugins/cmb2/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/cmb2",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}