Get Custom Field Values [get-custom-field-values] < 4.1
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Reilly Get Custom Field Values plugin <= 4.0.1 versions.
- Affected:
- up to 4.1
- Fixed in:
- 4.1
- Disclosed:
- Oct 18, 2023
CVE-2023-45604 on NVD →
Get Custom Field Values <= 4.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin widget
medium
The Get Custom Field Values plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin widget in versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject...
- CVSS:
- 5.5
- Affected:
- up to 4.0.1
- Fixed in:
- 4.1
- Disclosed:
- Oct 11, 2023
CVE-2023-45604 on NVD →
Get Custom Field Values <= 4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Custom Meta Widget
medium
The Get Custom Field Values plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Meta fields in versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level a...
- CVSS:
- 6.4
- Affected:
- up to 4.1
- Fixed in:
- 4.1
- Disclosed:
- Oct 10, 2023
Get Custom Field Values [get-custom-field-values] < 4.1
unknown
The Get Custom Field Values plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Meta fields in versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level a...
- Affected:
- up to 4.1
- Fixed in:
- 4.1
- Disclosed:
- Oct 10, 2023
Get Custom Field Values [get-custom-field-values] < 4.0.1
unknown
[en] The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.1
- Disclosed:
- Dec 13, 2021
CVE-2021-24871 on NVD →
Get Custom Field Values [get-custom-field-values] < 4.0
unknown
[en] The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Dec 13, 2021
CVE-2021-24872 on NVD →
Get Custom Field Values < 4.0 - Arbitrary Post Metadata Access
medium
The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.
- CVSS:
- 6.5
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Nov 9, 2021
CVE-2021-24872 on NVD →
Get Custom Field Values <= 4.0.0 - Contributor+ Stored Cross-Site Scripting
medium
The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks
- CVSS:
- 6.4
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.1
- Disclosed:
- Nov 9, 2021
CVE-2021-24871 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database