PT-2026-95764 · WordPress · Secure Custom Fields
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Secure Custom Fields WordPress plugin versions prior to 6.9.4
Description
An issue exists where the plugin fails to properly verify that a front-end form submission matches the form rendered to the visitor. This allows unauthenticated users to submit data against a different registered form, enabling the modification of the title and content of the post associated with that form.
Recommendations
Update the Secure Custom Fields WordPress plugin to version 6.9.4 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Secure Custom Fields