Custom Field Suite [custom-field-suite] <= 2.6.7 (unfixed + closed)
unknown
[en] The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the eval() function. This makes it possible for authenticated attackers, with con...
- Affected:
- up to 2.6.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2024
CVE-2024-3562 on NVD →
Custom Field Suite [custom-field-suite] <= 2.6.7 (unfixed + closed)
unknown
[en] The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abo...
- Affected:
- up to 2.6.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2024
CVE-2024-3558 on NVD →
Custom Field Suite [custom-field-suite] <= 2.6.7 (unfixed + closed)
unknown
[en] The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...
- Affected:
- up to 2.6.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2024
CVE-2024-3561 on NVD →
Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via cfs[post_title]
medium
The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, t...
- CVSS:
- 6.4
- Affected:
- up to 2.6.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2024
CVE-2024-3558 on NVD →
Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) PHP Code Injection via Loop Custom Field
high
The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the eval() function. This makes it possible for authenticated attackers, with contribu...
- CVSS:
- 8.8
- Affected:
- up to 2.6.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2024
CVE-2024-3562 on NVD →
Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) SQL Injection via Term Custom Field
high
The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attac...
- CVSS:
- 8.8
- Affected:
- up to 2.6.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2024
CVE-2024-3561 on NVD →
Custom Field Suite [custom-field-suite] <= 2.6.7 (unfixed + closed)
unknown
[en] The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and a...
- Affected:
- up to 2.6.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 12, 2024
CVE-2024-3559 on NVD →
Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via cfs[post_content]
medium
The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...
- CVSS:
- 6.4
- Affected:
- up to 2.6.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 11, 2024
CVE-2024-3559 on NVD →
Custom Field Suite [custom-field-suite] < 2.6.6 (closed)
unknown
[en] The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level acce...
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.6
- Disclosed:
- May 9, 2024
CVE-2024-3068 on NVD →
Custom Field Suite <= 2.6.5 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, t...
- CVSS:
- 4.4
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.6
- Disclosed:
- May 7, 2024
CVE-2024-3068 on NVD →
Custom Field Suite [custom-field-suite] < 2.6.5 (closed)
unknown
[en] The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the meta values. This makes it possible for authenticated attackers, with administrator-level permissi...
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.5
- Disclosed:
- Feb 29, 2024
CVE-2024-0689 on NVD →
Custom Field Suite <= 2.6.4 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the meta values. This makes it possible for authenticated attackers, with administrator-level permissions a...
- CVSS:
- 4.4
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.5
- Disclosed:
- Feb 28, 2024
CVE-2024-0689 on NVD →
Custom Field Suite [custom-field-suite] < 2.6.3 (closed)
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions.
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- May 18, 2023
CVE-2023-32515 on NVD →
Custom Field Suite <= 2.6.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field values in versions up to, and including, 2.6.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitra...
- CVSS:
- 4.4
- Affected:
- up to 2.6.2.1
- Fixed in:
- 2.6.3
- Disclosed:
- May 10, 2023
CVE-2023-32515 on NVD →
Custom Field Suite [custom-field-suite] < 2.5.15 (closed)
unknown
[en] The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.
- Affected:
- up to 2.5.15
- Fixed in:
- 2.5.15
- Disclosed:
- May 10, 2019
CVE-2019-11871 on NVD →
Custom Field Suite <= 2.5.14 - Authenticated Cross-Site Scripting
medium
The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.
- CVSS:
- 5.4
- Affected:
- up to 2.5.14
- Fixed in:
- 2.5.15
- Disclosed:
- May 8, 2019
CVE-2019-11871 on NVD →
Custom Field Suite <= 2.4 - Missing Authorization
medium
The Custom Field Suite plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in the ajax_handler() function in versions up to, and including, 2.4.1 This makes it possible for unauthorized attackers to access and execute otherwise restricted AJAX actions, such as importing and expor...
- CVSS:
- 6.3
- Affected:
- up to 2.4
- Fixed in:
- 2.4.1
- Disclosed:
- Mar 12, 2015
Custom Field Suite [custom-field-suite] < 2.4.1 (closed)
unknown
Because of this vulnerability, attacker can import and export custom fields.
Update the plugin.
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Mar 12, 2015
Custom Field Suite [custom-field-suite] < 2.4.1 (closed)
unknown
The Custom Field Suite plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in the ajax_handler() function in versions up to, and including, 2.4.1 This makes it possible for unauthorized attackers to access and execute otherwise restricted AJAX actions, such as importing and expor...
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Mar 12, 2015
Custom Field Suite [custom-field-suite] < 2.4.1 (closed)
unknown
Any authenticated user is able to import and export Custom Field Suite config via AJAX.
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database