Junglewise Threat Intelligence

CVE-2026-6252: WordPress Meta Field Block stored XSS in tagName attribute

CVE-2026-6252 · Severity: medium · CVSS 6.4 · Published 2026-05-14

Executive brief

The Meta Field Block plugin for WordPress, which allows site owners to display custom data fields on their pages, contains a security flaw. This vulnerability allows users with basic contributor-level access to inject malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.

Technical details

The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'tagName' block attribute. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting malicious JavaScript into the block settings. Because the 'tagName' attribute is not properly validated, the script is stored in the database and executed in the browser of any user who views the affected page. This vulnerability is present in all versions up to 1.5.2 and was addressed in version 1.5.3.

Affected products

  • WordPress plugin Meta Field Block up to, and including, 1.5.2

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory

References