← WordPress Vulnerabilities
WordPress security by component

Meta Field Block – Display custom fields in the Block Editor without coding

Meta Field Block displays custom field values as blocks within the WordPress block editor.

Meta Field Block – Display custom fields in the Block Editor without coding (display-a-meta-field-as-block) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published May 28, 2026; the highest published CVSS base score is 6.5.

Plugin slug: display-a-meta-field-as-block

CVE-2026-3173: Meta Field Block – Display custom fields in the Block Editor without coding: Broken access control

Meta Field Block – Display custom fields in the Block Editor without coding is affected by broken access control. Exploitation requires an authenticated contributor account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 1.5.1.

PublishedMay 28, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for display-a-meta-field-as-block
Safe version
May 28, 2026 CVE-2026-3173
Meta Field Block – Display custom fields in the Block Editor without coding: Broken access control
Meta Field Block – Display custom fields in the Block Editor without coding is affected by broken access control. Exploitation requires an authenticated contributor account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 1.5.1.
See mitigation notes
CVE6.5
NVDPending
Aug 18, 2024 CVE-2024-43278
Meta Field Block: Cross-site scripting
Meta Field Block is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending