CVE-2026-14488 is a critical missing authorization (CWE-862) vulnerability in the Meta Box AIO WordPress plugin, affecting its MB Frontend Submission extension. The flaw allows unauthenticated, remote attackers to delete arbitrary posts and pages on affected sites, resulting in a high impact to data integrity and availability. It carries a CVSS v3.1 base score of 9.1 (Critical).
