plugin

Get Custom Field Values Vulnerabilities

8 known security issues reported for the Get Custom Field Values WordPress plugin. Most recent disclosed Oct 18, 2023.

4 medium

Running Get Custom Field Values on your site? Check whether your installed version is affected.

Scan your site free

Get Custom Field Values [get-custom-field-values] < 4.1

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Reilly Get Custom Field Values plugin <= 4.0.1 versions.

Affected:
up to 4.1
Fixed in:
4.1
Disclosed:
Oct 18, 2023

CVE-2023-45604 on NVD →

Get Custom Field Values <= 4.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin widget

medium

The Get Custom Field Values plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin widget in versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject...

CVSS:
5.5
Affected:
up to 4.0.1
Fixed in:
4.1
Disclosed:
Oct 11, 2023

CVE-2023-45604 on NVD →

Get Custom Field Values <= 4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Custom Meta Widget

medium

The Get Custom Field Values plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Meta fields in versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level a...

CVSS:
6.4
Affected:
up to 4.1
Fixed in:
4.1
Disclosed:
Oct 10, 2023

Get Custom Field Values [get-custom-field-values] < 4.1

unknown

The Get Custom Field Values plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Meta fields in versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level a...

Affected:
up to 4.1
Fixed in:
4.1
Disclosed:
Oct 10, 2023

Get Custom Field Values [get-custom-field-values] < 4.0.1

unknown

[en] The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

Affected:
up to 4.0.1
Fixed in:
4.0.1
Disclosed:
Dec 13, 2021

CVE-2021-24871 on NVD →

Get Custom Field Values [get-custom-field-values] < 4.0

unknown

[en] The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.

Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Dec 13, 2021

CVE-2021-24872 on NVD →

Get Custom Field Values < 4.0 - Arbitrary Post Metadata Access

medium

The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.

CVSS:
6.5
Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Nov 9, 2021

CVE-2021-24872 on NVD →

Get Custom Field Values <= 4.0.0 - Contributor+ Stored Cross-Site Scripting

medium

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

CVSS:
6.4
Affected:
up to 4.0.1
Fixed in:
4.0.1
Disclosed:
Nov 9, 2021

CVE-2021-24871 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database