Junglewise Threat Intelligence

CVE-2026-3173: WordPress Meta Field Block IDOR in block attributes

CVE-2026-3173 · Severity: medium · CVSS 6.5 · Published 2026-05-28

Vendors: Wordpress.

Executive brief

The Meta Field Block plugin for WordPress, which allows site owners to display custom data fields on their pages, contains a security flaw that allows certain logged-in users to view private information. An attacker with basic contributor-level access could exploit this to read sensitive data stored in the database, such as customer names, email addresses, and physical addresses from other plugins like WooCommerce. This could lead to a significant data breach and exposure of personally identifiable information (PII).

Technical details

The Meta Field Block plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient authorization checks in its block attributes. Specifically, the plugin allows users to specify arbitrary object IDs and object types via block attributes without validating if the requesting user has the appropriate permissions to access that specific object's metadata. An authenticated attacker with Contributor-level permissions or higher can exploit this to retrieve arbitrary user meta, post meta, and term meta data. This can result in the exposure of sensitive information, including PII stored by third-party plugins like WooCommerce. The issue is addressed in versions following 1.5.1.

Affected products

  • WordPress Meta Field Block up to, and including, 1.5.1

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References