plugin

Custom Field Suite Vulnerabilities

20 known security issues reported for the Custom Field Suite WordPress plugin. Most recent disclosed Jun 20, 2024.

2 high 7 medium

Running Custom Field Suite on your site? Check whether your installed version is affected.

Scan your site free

Custom Field Suite [custom-field-suite] <= 2.6.7 (unfixed + closed)

unknown

[en] The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the eval() function. This makes it possible for authenticated attackers, with con...

Affected:
up to 2.6.7
Fix:
No patched version reported
Disclosed:
Jun 20, 2024

CVE-2024-3562 on NVD →

Custom Field Suite [custom-field-suite] <= 2.6.7 (unfixed + closed)

unknown

[en] The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abo...

Affected:
up to 2.6.7
Fix:
No patched version reported
Disclosed:
Jun 20, 2024

CVE-2024-3558 on NVD →

Custom Field Suite [custom-field-suite] <= 2.6.7 (unfixed + closed)

unknown

[en] The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...

Affected:
up to 2.6.7
Fix:
No patched version reported
Disclosed:
Jun 20, 2024

CVE-2024-3561 on NVD →

Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via cfs[post_title]

medium

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, t...

CVSS:
6.4
Affected:
up to 2.6.7
Fix:
No patched version reported
Disclosed:
Jun 19, 2024

CVE-2024-3558 on NVD →

Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) PHP Code Injection via Loop Custom Field

high

The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the eval() function. This makes it possible for authenticated attackers, with contribu...

CVSS:
8.8
Affected:
up to 2.6.7
Fix:
No patched version reported
Disclosed:
Jun 19, 2024

CVE-2024-3562 on NVD →

Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) SQL Injection via Term Custom Field

high

The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attac...

CVSS:
8.8
Affected:
up to 2.6.7
Fix:
No patched version reported
Disclosed:
Jun 19, 2024

CVE-2024-3561 on NVD →

Custom Field Suite [custom-field-suite] <= 2.6.7 (unfixed + closed)

unknown

[en] The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and a...

Affected:
up to 2.6.7
Fix:
No patched version reported
Disclosed:
Jun 12, 2024

CVE-2024-3559 on NVD →

Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via cfs[post_content]

medium

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...

CVSS:
6.4
Affected:
up to 2.6.7
Fix:
No patched version reported
Disclosed:
Jun 11, 2024

CVE-2024-3559 on NVD →

Custom Field Suite [custom-field-suite] < 2.6.6 (closed)

unknown

[en] The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level acce...

Affected:
up to 2.6.6
Fixed in:
2.6.6
Disclosed:
May 9, 2024

CVE-2024-3068 on NVD →

Custom Field Suite <= 2.6.5 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, t...

CVSS:
4.4
Affected:
up to 2.6.5
Fixed in:
2.6.6
Disclosed:
May 7, 2024

CVE-2024-3068 on NVD →

Custom Field Suite [custom-field-suite] < 2.6.5 (closed)

unknown

[en] The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the meta values. This makes it possible for authenticated attackers, with administrator-level permissi...

Affected:
up to 2.6.5
Fixed in:
2.6.5
Disclosed:
Feb 29, 2024

CVE-2024-0689 on NVD →

Custom Field Suite <= 2.6.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the meta values. This makes it possible for authenticated attackers, with administrator-level permissions a...

CVSS:
4.4
Affected:
up to 2.6.4
Fixed in:
2.6.5
Disclosed:
Feb 28, 2024

CVE-2024-0689 on NVD →

Custom Field Suite [custom-field-suite] < 2.6.3 (closed)

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions.

Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
May 18, 2023

CVE-2023-32515 on NVD →

Custom Field Suite <= 2.6.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field values in versions up to, and including, 2.6.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitra...

CVSS:
4.4
Affected:
up to 2.6.2.1
Fixed in:
2.6.3
Disclosed:
May 10, 2023

CVE-2023-32515 on NVD →

Custom Field Suite [custom-field-suite] < 2.5.15 (closed)

unknown

[en] The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.

Affected:
up to 2.5.15
Fixed in:
2.5.15
Disclosed:
May 10, 2019

CVE-2019-11871 on NVD →

Custom Field Suite <= 2.5.14 - Authenticated Cross-Site Scripting

medium

The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.

CVSS:
5.4
Affected:
up to 2.5.14
Fixed in:
2.5.15
Disclosed:
May 8, 2019

CVE-2019-11871 on NVD →

Custom Field Suite <= 2.4 - Missing Authorization

medium

The Custom Field Suite plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in the ajax_handler() function in versions up to, and including, 2.4.1 This makes it possible for unauthorized attackers to access and execute otherwise restricted AJAX actions, such as importing and expor...

CVSS:
6.3
Affected:
up to 2.4
Fixed in:
2.4.1
Disclosed:
Mar 12, 2015

Custom Field Suite [custom-field-suite] < 2.4.1 (closed)

unknown

Because of this vulnerability, attacker can import and export custom fields. Update the plugin.

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Mar 12, 2015

Custom Field Suite [custom-field-suite] < 2.4.1 (closed)

unknown

The Custom Field Suite plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in the ajax_handler() function in versions up to, and including, 2.4.1 This makes it possible for unauthorized attackers to access and execute otherwise restricted AJAX actions, such as importing and expor...

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Mar 12, 2015

Custom Field Suite [custom-field-suite] < 2.4.1 (closed)

unknown

Any authenticated user is able to import and export Custom Field Suite config via AJAX.

Affected:
up to 2.4.1
Fixed in:
2.4.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database