Skip to content

[GHSA-m4q3-832v-44j6] The Meta Box plugin for WordPress is vulnerable to...#7143

Merged
advisory-database[bot] merged 1 commit intoictbeheer/advisory-improvement-7143from
ictbeheer-GHSA-m4q3-832v-44j6
Mar 10, 2026
Merged

[GHSA-m4q3-832v-44j6] The Meta Box plugin for WordPress is vulnerable to...#7143
advisory-database[bot] merged 1 commit intoictbeheer/advisory-improvement-7143from
ictbeheer-GHSA-m4q3-832v-44j6

Conversation

@ictbeheer
Copy link

Updates

  • Affected products
  • Summary

Comments
Add package name

Copilot AI review requested due to automatic review settings March 10, 2026 11:00
@github-actions github-actions bot changed the base branch from main to ictbeheer/advisory-improvement-7143 March 10, 2026 11:02
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the GHSA advisory metadata for the Meta Box WordPress plugin vulnerability by adding package/affected information and a clearer summary.

Changes:

  • Added a summary describing the affected versions and impact.
  • Populated the affected array with a Packagist package and fixed version range.
  • Updated the modified timestamp.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

You can also share your feedback on Copilot code review. Take the survey.

"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
Copy link

Copilot AI Mar 10, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CVSS vector indicates PR:H (High privileges required), but the details state the attack is possible with "Contributor-level access and above", which is typically not “High” privileges. Update the CVSS vector to match the described privilege requirement (or adjust the details if PR:H is intentional).

Suggested change
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"

Copilot uses AI. Check for mistakes.
{
"package": {
"ecosystem": "Packagist",
"name": "wpmetabox/meta-box"
Copy link

Copilot AI Mar 10, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please confirm the package identifier matches the canonical Packagist package name. If this is a WordPress plugin that isn’t actually published under wpmetabox/meta-box on Packagist, downstream tooling may fail to associate the advisory with the correct package; use the correct Packagist name (or the appropriate ecosystem/package identity supported by your schema).

Suggested change
"name": "wpmetabox/meta-box"
"name": "meta-box/meta-box"

Copilot uses AI. Check for mistakes.
@advisory-database advisory-database bot merged commit 06fb20b into ictbeheer/advisory-improvement-7143 Mar 10, 2026
7 of 8 checks passed
@advisory-database
Copy link
Contributor

Hi @ictbeheer! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the ictbeheer-GHSA-m4q3-832v-44j6 branch March 10, 2026 19:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants