PT-2026-95764 · WordPress · Secure Custom Fields

·

CVE-2026-92403

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Secure Custom Fields WordPress plugin versions prior to 6.9.4
Description An issue exists where the plugin fails to properly verify that a front-end form submission matches the form rendered to the visitor. This allows unauthenticated users to submit data against a different registered form, enabling the modification of the title and content of the post associated with that form.
Recommendations Update the Secure Custom Fields WordPress plugin to version 6.9.4 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92403

Affected Products

Secure Custom Fields