# CMB2 <= 2.13.2 - Authenticated (Editor+) Limited Options Update via REST API 'object_type' and 'object_id' Parameters

- **ID:** WPSEC-2026-0552
- **Plugin:** CMB2 (`cmb2`), https://wordpress.org/plugins/cmb2/
- **Affected versions:** from 2.2.3 before 2.13.3
- **Fixed in:** 2.13.3 (Update to 2.13.3 or later.)
- **Severity:** Medium 5.0 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/cmb2
- **Fix released:** 2026-10-03
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0552/

## Description

The CMB2 plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.2.3 up to, and including, 2.13.2. This is due to the REST API boxes/fields endpoints applying the user-supplied 'object_type' and 'object_id' parameters to a box without checking them against the object types and option keys the box is registered for. On sites where a plugin or theme registers a CMB2 box with REST API write access, authenticated attackers with editor-level access and above can write or delete the box's field values on object types the box was not registered for, including any entry in the wp_options table, which can corrupt core settings and make the site inaccessible. Through the same parameters, values stored under a REST-readable field's ID on other objects and options can also be read. The minimum role depends on the box's permission callbacks and defaults to users with the edit_others_posts capability.

## References

- https://wpsec.com/vuln/WPSEC-2026-0552/
- https://plugins.svn.wordpress.org/cmb2/tags/2.13.3/
- https://wordpress.org/plugins/cmb2/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0552/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
