WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Post Meta Data Manager

View, modify, search, and delete post meta, user meta, and taxonomy meta right from your WordPress edit screens—all without ever touching the database …

6Reported vulnerabilities
8.8Highest CVSS score
1.5.0Latest version
1,000+Active installs

What to do now

Update Post Meta Data Manager to 1.3.0 or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: April 3, 2026 / Tested up to WordPress: 6.8.8 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-5776 High 8.8 0.3% Before 1.2.2 1.2.2 November 21, 2023
CVE-2023-5425 High 8.8 0.5% Before 1.2.1 1.2.1 October 28, 2023
CVE-2023-5426 High 7.5 0.5% Before 1.2.1 1.2.1 October 28, 2023
CVE-2024-13835 High 7.2 0.4% 1.4.3 and earlier March 8, 2025
CVE-2024-6264 Medium 5.4 0.3% Before 1.3.0 1.3.0 July 2, 2024
WF-1958c166-282d-4469-b79d-4e959e0492c1 Medium 5.3 1.2.0 and earlier 1.2.1 October 20, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.