Insecure Direct Object Reference in Meta Field Block Plugin for WordPress
CVE-2026-3173

6.5MEDIUM

What is CVE-2026-3173?

The Meta Field Block plugin for WordPress has a vulnerability that allows authenticated users with Contributor-level permissions and above to exploit the lack of validation for object IDs and types specified in block attributes. This oversight can lead to unauthorized access to sensitive metadata across various objects within the database. Particularly concerning is the potential exposure of Personally Identifiable Information (PII) such as names, email addresses, and other private details, especially when used in conjunction with plugins that manage sensitive data like WooCommerce.

Affected Version(s)

Meta Field Block – Display custom fields in the Block Editor without coding 0 <= 1.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osvaldo Noe Gonzalez Del Rio
.