Meta Field Block WordPress Plugin Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Meta Field Block plugin for WordPress, affecting all versions through 1.5.1. The vulnerability arises because the plugin permits users to input arbitrary object IDs and types via block attributes without verifying if the user has the necessary permissions to access the object's metadata. This flaw enables authenticated attackers with Contributor-level access or higher to read user meta, post meta, and term meta data from any object in the database. On sites using plugins that store sensitive information in meta fields, such as WooCommerce, this could result in the exposure of Personally Identifiable Information (PII) like names, email addresses, phone numbers, and physical addresses.

Impact

Exploitation of this vulnerability could lead to unauthorized access and exposure of sensitive user metadata, including Personally Identifiable Information (PII) such as names, email addresses, phone numbers, and physical addresses, especially on sites using WooCommerce.

Remediation

Users are advised to update the Meta Field Block plugin to version 1.5.2 or later.

Added: May 28, 2026, 6:31 AM
Updated: May 28, 2026, 6:31 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.9
remediation
0.0
relevance
9.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.