plugin

Just Custom Fields Vulnerabilities

8 known security issues reported for the Just Custom Fields WordPress plugin. Most recent disclosed Jan 2, 2025.

4 medium

Running Just Custom Fields on your site? Check whether your installed version is affected.

Scan your site free

Just Custom Fields [just-custom-fields] <= 3.3.2 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in JustCoded / Alex Prokopenko Just Custom Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Just Custom Fields: from n/a through 3.3.2.

Affected:
up to 3.3.2
Fix:
No patched version reported
Disclosed:
Jan 2, 2025

CVE-2023-46203 on NVD →

Just Custom Fields [just-custom-fields] <= 3.3.2 (unfixed + closed)

unknown

[en] The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke this funct...

Affected:
up to 3.3.2
Fix:
No patched version reported
Disclosed:
Jul 9, 2024

CVE-2024-6167 on NVD →

Just Custom Fields [just-custom-fields] <= 3.3.2 (unfixed + closed)

unknown

[en] The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on several AJAX function. This makes it possible for unauthenticated attackers to invoke this functionality intended for admin us...

Affected:
up to 3.3.2
Fix:
No patched version reported
Disclosed:
Jul 9, 2024

CVE-2024-6168 on NVD →

Just Custom Fields <= 3.3.2 - Missing Authorization via AJAX actions

medium

The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke this functional...

CVSS:
4.3
Affected:
up to 3.3.2
Fix:
No patched version reported
Disclosed:
Jul 8, 2024

CVE-2024-6167 on NVD →

Just Custom Fields <= 3.3.2 - Cross-Site Request Forgery via AJAX actions

medium

The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on several AJAX function. This makes it possible for unauthenticated attackers to invoke this functionality intended for admin users v...

CVSS:
4.3
Affected:
up to 3.3.2
Fix:
No patched version reported
Disclosed:
Jul 8, 2024

CVE-2024-6168 on NVD →

Just Custom Fields <= 3.3.2 - Cross-Site Request Forgery on AJAX Actions

medium

The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on multiple AJAX actions. This makes it possible for unauthenticated attackers to create, modify, and delete custom fields via a forge...

CVSS:
4.3
Affected:
up to 3.3.2
Fix:
No patched version reported
Disclosed:
Oct 19, 2023

Just Custom Fields <= 3.3.2 - Missing Authorization on AJAX Actions

medium

The Just Custom Fields plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on various AJAX actions in versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to create, modify, and delete cust...

CVSS:
4.3
Affected:
up to 3.3.2
Fix:
No patched version reported
Disclosed:
Oct 19, 2023

CVE-2023-46203 on NVD →

Just Custom Fields [just-custom-fields] <= 3.3.2 (unfixed + closed)

unknown

The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on multiple AJAX actions. This makes it possible for unauthenticated attackers to create, modify, and delete custom fields via a forge...

Affected:
up to 3.3.2
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database