Hi,
WP Toolkit/Patchstack is currently warning about CVE-2026-39761, described as a privilege escalation vulnerability affecting Meta Box AIO versions up to and including 3.7.1.
I am currently running Meta Box AIO 3.12.0.
Could you please clarify whether version 3.12.0 is affected by CVE-2026-39761? If not, in which version was this vulnerability fixed?
Patchstack currently states that there is “no official patch available”, so it is unclear whether later versions such as 3.12.0 are considered safe or simply have not yet been verified.
Many thanks,
Bengt