plugin

Custom Metas Vulnerabilities

1 known security issue reported for the Custom Metas WordPress plugin. Most recent disclosed Apr 17, 2016.

1 medium

Running Custom Metas on your site? Check whether your installed version is affected.

Scan your site free

Custom Metas <= 1.5.1 - Reflected Cross-Site Scripting

medium

The Custom Metas plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘/wp-content/plugins/custom-metas/tpl/meta-data-form-multiple.php' file in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitra...

CVSS:
6.1
Affected:
up to 1.5.1
Fix:
No patched version reported
Disclosed:
Apr 17, 2016

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database