---
id: CVE-2026-80338
title: >-
  The CMB2 WordPress plugin before 2.13.0 does not perform any capability check
  on one of its AJAX actions, allowing users with a role as low as Subscriber to
  create arbitrary WordPress options and corrupt existing ones, which can break
  co…
summary: >-
  The CMB2 WordPress plugin before 2.13.0 does not perform any capability check
  on one of its AJAX actions, allowing users with a role as low as Subscriber to
  create arbitrary WordPress options and corrupt existing ones, which can break
  co…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-862
product: CMB2
affected:
  - CMB2 < 2.13.0
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:42:02.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80338'
references:
  - url: 'https://wpscan.com/vulnerability/7402e0b0-54de-42b3-9032-ae225fb4e76a/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T10:37:26.261371Z'
ingestedAt: '2026-09-24T06:39:26.611Z'
---

## Overview

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break core site settings and take the site offline.
Exploitation requires the site's  or another CMB2 WordPress plugin before 2.13.0 to have declared an oEmbed field, as the CMB2 WordPress plugin before 2.13.0 registers none of its own. The stored value is never attacker-controlled, so the issue does not lead to privilege escalation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
