300,000+
September 24, 2026
September 16, 2014
CMB2 is a developer’s toolkit for building metaboxes, custom fields, and forms for WordPress that will blow your mind. Easily manage meta for posts, terms, users, comments, or create custom option pages.
CMB2 is a complete rewrite of Custom Metaboxes and Fields for WordPress. To get started, please follow the examples in the included example-functions.php file and have a look at the basic usage instructions.
You can see a list of available field types here.
Development occurs on Github, and all contributions welcome. Please read the CONTRIBUTING doc for more details.
A complete list of all our awesome contributors found here: github.com/CMB2/CMB2/graphs/contributors
If you are looking to provide language translation files, Please do so via WordPress Plugin Translations.
Custom Field Types
custom_attached_posts, for attaching posts to a page.post_search_ajax Attach posts to each other. Same approach as CMB2 Attached Posts Field but with Ajax request, multiple/single option, and different UI.user_search_text adds a user-search dialog for searching/attaching other User IDs.CMB2 Field Type: Google Maps from mustardBees: Custom field type for Google Maps.
The
pw_mapfield stores the latitude/longitude values which you can then use to display a map in your theme.
CMB2 Field Type: Leaflet Maps from villeristi: Custom field type for Leaflet Maps.
CMB2 Field Type: Select2 from mustardBees: Custom field types which use the Select2 script:
- The
pw_select fieldacts much like the default select field. However, it adds typeahead-style search allowing you to quickly make a selection from a large list- The
pw_multiselectfield allows you to select multiple values with typeahead-style search. The values can be dragged and dropped to reorder
CMB Field Type: Slider from mattkrupnik: Adds a jQuery UI Slider field.
'apply_term' => false) to disable and save the term ids as data instead (like for options pages, etc).select field. However, it adds the support for optgroup and saving of values with multiple attribute.Other Helpful Resources
If installing the plugin from wordpress.org:
/CMB2 directory to the /wp-content/plugins/ directory.example-functions.php into to your theme or plugin’s directory.If including the library in your plugin or theme:
example-functions.php into a folder above the CMB directory OR copy the entirety of its contents to your theme’s functions.php file.FAQ’s usually end up in the github wiki.
file_list field values, which were previously stored and rendered verbatim. Array keys must now be positive-integer attachment IDs, and URLs are sanitized with the field’s protocols on save and on render. Entries with a malformed key (including 0 and positional-list keys) or a URL that sanitizes to empty are dropped the next time the field is saved. Props Ivaylo (via Wordfence).TypeError when displaying a file_list field containing a non-scalar value.sanitize_callback, which wp.org’s Plugin Check requires of every register_setting() call. It is a passthrough by design: values are already sanitized per field type before the option is saved. Props @rubengc (#1533).en@pirate translation files, whose @ in the filename fails wp.org’s plugin submission checks for any plugin bundling CMB2. Props @rubengc (#1533).rest_read_capability box property (also accepted as a field parameter) which declares who may read a box, or a single field on it, through the CMB2 REST API. The values read as plain English: false means no one, true means everyone (logged-out visitors included), 'box-capability' means holders of the box’s own capability parameter, and any other capability string means holders of that capability, e.g. 'edit_posts'. It cascades field box default the same way show_in_rest does, and the existing cmb2_api_get_box_permissions_check/cmb2_api_get_field_permissions_check filters still run afterward and have the final say. See REST API Read Permissions (#1563).cmb2_rest_enforce_options_page_read_permissions filter which aligns REST reads of options-page boxes with WordPress core’s settings/options convention, gating them behind the box capability rather than serving them publicly. It defaults to false, preserving CMB2’s current behavior, and is only consulted for boxes which have not declared a rest_read_capability. See REST API Read Permissions (#1563).rest_read_capability on it nor enabled the filter above. It links the REST API Read Permissions guide so those sites can pick the setting they want ahead of a later default change (#1563).SECURITY.md security policy and enabled GitHub private vulnerability reporting, giving researchers a private channel that does not depend on email delivery.edit_post, edit_user, edit_comment, the taxonomy’s edit_terms, or, for an options-page target, the capability of the box that declared that option key) instead of relying on the nonce alone, and sanitizes the requested object type. Props Mutantgun (#1563).CMB2_Base::maybe_hook_parameter() turning a caller’s default value into a declared box/field parameter. It passed the default through to prop(), which caches a truthy fallback on the object, so one request’s default persisted as a real parameter for every later call. Only a declared parameter is consulted now (#1563).field_id input (with an isset() guard) and escaped the rel attribute in the oEmbed AJAX handler, addressing a reflected XSS vector flagged by WordPress Plugin Check. Props @thisismyurl (#1559).id and data-selector attributes) with esc_attr(), resolving unescaped HTML attribute output flagged by WordPress Coding Standards. Props @thisismyurl (#1560).@wordpress/env (wp-env) on pinned ports, running both PHPUnit and Playwright through it. (#1554, #1558).install-wp-tests.sh for modern WordPress. (#1555).textarea-based field (passing null to wp_kses_post()). Props @baljindersingh88 (#1537).ltrim() deprecation in the taxonomy field display.#[AllowDynamicProperties] to the class roots..cmb2-wrap inputs that caused unexpected input styling. Fixes #1556/wordpress.org/support/topic/weird-checkbox-behaviour-on-wp-7 (#1557).object_id and mb_object_type and in do_scripts – Allows overriding by plugins/libs. (Added to support the new CMB2 WooCommerce HPOS Orders extension)cmb2_init_hooks hook when hookup is called.DateTime field values (text_datetime_timestamp_timezone field type only). (#1510)https. Props @paulschreiber (#1413).shiftRows functionality to be simpler, and fix issues with JS initialization. Fixes #1426 and #1431.Required parameter $i follows optional parameter $args.... Props @carloswph (#1417).cmb2_tab_group_tabs filter for adding arbitrary menu page urls to the cmb2 tabs, and move tab markup output to separate method, CMB2_Options_Hookup::options_page_tab_nav_output(). Fixes #1407.get_allowed_mime_types(), which makes SVGs more reliable when using the Safe SVG plugin. Fixes #1223.func_get_args(). Fixes #1389.5 instead of the default 10, causing some back-compatibility issues. Fixes #1410.enqueue wp-color-picker is enqueued for color fields. Props @rubengc (#1339).'file_list' buttons. Props @pgroot91 (#1347).wysiwyg field type not working in a group, by ensuring scripts properly enqueued. Props @yoren (#1361).$object_id doc block types in helper-functions.php. Fixes #1365.PHP Deprecated: Required parameter $field_id follows optional parameter $type, due to changes in PHP 8.0. Fixes #1396.deprecated_param method in PHP 7.4. Props @jonathanstegall (#1400).'column' => array( 'disable_sortable' => true ). Props @RubenMartins (#1281).'taxonomy_select_hierarchical'. Fixes #751text, textarea and wysiwyg character counter options. For now, this feature is not available to wysiwyg field types within repeatable groups. Props @gyrus (#1276).
'char_counter' – Defaults to false, no counter. Set to true, or words to count words instead of characters.'char_max' – integer. When defined, counter shows remaining characters/words.'char_max_enforce' – boolean, default: false. Currently only applied (as maxlength attribute) to text and textarea fields which use 'characters' for counter.'words_left_text' – Default: “Words left”'words_text' – Default: “Words”'characters_left_text' – Default: “Characters left”'characters_text' – Default: “Characters”'characters_truncated_text' – Default: “Your text may be truncated.”register_rest_field_cb, which when used allows overriding the way CMB2 handles the register_rest_field callbacks, and defining your own REST prefix for your fields. See this PR comment for more context.CMB2_hookup to CMB2_Hookup. Classes are case-insensitive, so this is a backwards-compatible change. Props @szepeviktor (#1330, #1328)."cmb2_display_class_{$fieldtype}" filter and 'display_class' field parameter to allow specifying the class to use to display the field (in admin columns, etc).CMB2_Types::_id() to allow not appending the iterator attribute if a repeatable field.CMB2_Utils::concat_attrs() test for nested arrays as data attributes.cmb2_add_row triggered event.CMB2_Field::get_rest_value() to get values for fields in the post REST API endpoints (#1284).file and text_datetime_timestamp_timezone field types, the supporting field data was not provided (e.g. the file id for file field, and the utc value for the text_datetime_timestamp_timezone field). Fixes https://wordpress.org/support/topic/cmb2-rest-api-image-file-field-as-an-object/.taxonomy_select_hierarchical now saves to the correct location, the term relationships table. Props @latheva (#1307)./wp/v2/{post_type}) would show all boxes for all custom post types even though not registered to the post-type. Props @Mte90 (#1238).function_exists( 'add_action' ) check to bootstrap file to ensure compatibility with composer usage. Props @salcode (#1271, #1270)get_user_locale() in admin area instead of get_locale(). Fixes #1267.CMB2::is_box_type() now also checks for taxonomies if box is registered to “term” object type. This should fix some issues where CMB2 term meta was not showing up in REST API requests to the term endpoints.rest_value_cb registering of filter. Props @lipemat (#1212).CMB2_Utils::filter_empty from CMB2::save_group_field is always an array. (#1026).postbox divs to ensure compatibility with scripts which expect ids there. Props @amans2k (#1108).CMB2_Option properties accessible. (#1052)'cmb2_before_field_row', "cmb2_before_{$field_type}_field_row", "cmb2_after_{$field_type}_field_row", 'cmb2_after_field_row'. Props @rubengc (#953).'cmb2_field_defaults', 'cmb2_field_arguments_raw', 'cmb2_field_arguments'. Props @jrfnl (#588).core/editor object does not exist (is undefined), causing incompatibility issues with Yoast and likely others. Fixes #1197sv_SE translation. Props @edvind (#370).'mb_callback_args' CMB2 box property which allows defining the $callback_args passed into add_meta_box(). This allows using defining the new Gutenberg/block-editor compatibility parameters. Fixes #1191cmb_init_pickers and cmb_init_code_editors Javascript events for allowing just-in-time configuration for pickers/editors.CMB2_Field::get_rest_value() method for sending value through several filters ('cmb2_get_rest_value', "cmb2_get_rest_value_{$field_type}", "cmb2_get_rest_value_for_{$field_id}" ) before sending to REST request.call_user_func. Props @manzoorwanijk (#1177).wysiwyg fields’ visual tab wouldn’t save content on Gutenberg/block-editor posts. Props @staurand (#1190 fixes #1156).remove_default wouldn’t actually remove the default taxonomy metabox when box registration used an alternate box context. Props @lipemat (#1147).textarea_code fields registered on the page. Fixes #1110.wysiwyg field values to string “false” when boolean false. Fixes #1138 (again!).'tab_group' CMB2 box property. This snippet demonstrates how to create a top-level menu options page with multiple submenu pages, each with the tabbed navigation. To specify a different tab title than the options-page title, set the 'tab_title' CMB2 box property. See #301, #627.zh-CN translation. Props @uicestone (#1089).nl_NL translation. Props @tammohaannl (#1101)."cmb2_should_autoload_{$options_key}") or via a box parameter for 'options-page' box registrations ('autoload' => false,). (#1093)'textarea_code' field type now uses CodeMirror that is used by WordPress (#1096). A field can opt-out to return to the previous behavior by specifying an 'options' parameter:
‘options’ => array( ‘disable_codemirror’ => true )
As with the other javascript-enabled fields, the code-editor defaults can be overridden via a data-codeeditor attribute. E.g:
`php
‘attributes’ => array(
‘data-codeeditor’ => json_encode( array(
‘codemirror’ => array(
‘mode’ => ‘css’,
),
) ),
),
`
resetBoxes/resetBox Javascript methods for resetting CMB2 box forms.CMB2_Boxes methods for filtering instances of CMB2, CMB2_Boxes::get_by( $property, $optional_compare ) and CMB2_Boxes::filter_by( $property, $to_ignore = null ).'taxonomy_*' fields when used for term fields/meta. Save the value to term-meta.Fatal error: Declaration of CMB2_Type_Colorpicker::render() must be compatible with CMB2_Type_Text::render($args = Array)...). (#1070, #1074, #1075).For the changelog of versions prior to 2.3.0, see CHANGELOG.md.