The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.
History

Thu, 15 May 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Metabox
Metabox meta Box
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:metabox:meta_box:*:*:*:*:*:wordpress:*:*
Vendors & Products Metabox
Metabox meta Box

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-04-15T05:00:02.873Z

Updated: 2024-08-01T18:33:25.079Z

Reserved: 2024-02-02T15:15:35.298Z

Link: CVE-2024-1204

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.079Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-15T05:15:14.723

Modified: 2025-05-15T13:40:27.707

Link: CVE-2024-1204

cve-icon Redhat

No data.