The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.
Loading...
Loading...
Score 4.3 from GitHub Security Advisory published 2024-04-15. NVD baseline CVSS 4.3; sources differ by 0.0.
The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.
April 15, 2024
May 15, 2025
Explore the affected products and dependency analysis for CVE-2024-1204
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.