← WordPress Vulnerabilities
WordPress security by component

Meta Field Block – Display custom fields in the Block Editor without coding

Meta Field Block – Display custom fields in the Block Editor without coding displays custom field values in the WordPress Block Editor without coding.

Meta Field Block – Display custom fields in the Block Editor without coding (meta-field-block) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published May 14, 2026; the highest published CVSS base score is 6.4.

Plugin slug: meta-field-block

CVE-2026-6252: Meta Field Block – Display custom fields in the Block Editor without coding: Cross-site scripting

Meta Field Block – Display custom fields in the Block Editor without coding is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.5.2.

PublishedMay 14, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for meta-field-block
Safe version
May 14, 2026 CVE-2026-6252
Meta Field Block – Display custom fields in the Block Editor without coding: Cross-site scripting
Meta Field Block – Display custom fields in the Block Editor without coding is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.5.2.
See mitigation notes
CVE6.4
NVDPending