# CMB2 <= 2.13.3 - Reflected Cross-Site Scripting via Object ID Request Parameters

- **ID:** WPSEC-2026-0729
- **Plugin:** CMB2 (`cmb2`), https://wordpress.org/plugins/cmb2/
- **Affected versions:** all versions before 2.13.4
- **Fixed in:** 2.13.4 (Update to 2.13.4 or later.)
- **Severity:** Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/cmb2
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0729/

## Description

The CMB2 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'user_id', 'tag_ID', 'c' and 'post' request parameters in all versions up to, and including, 2.13.3. The plugin uses these values as the box object ID after only sanitize_text_field(), which keeps quotes, and outputs them unescaped in the oembed field's single-quoted data-objectid attribute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into admin edit screens (such as the user profile or term edit screen) that render a CMB2 box with an oembed field. The scripts run if the attacker can trick a logged-in user, such as an administrator, into performing an action like clicking on a link.

## References

- https://wpsec.com/vuln/WPSEC-2026-0729/
- https://plugins.svn.wordpress.org/cmb2/tags/2.13.4/
- https://wordpress.org/plugins/cmb2/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0729/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
