rootpwn

low · CVSS v3 3.7 · EPSS 0.00136

CVE-2026-92403

The Secure Custom Fields WordPress plugin before version 6.9.4 fails to properly verify front-end form submissions against the originally re

Overview

The Secure Custom Fields WordPress plugin before version 6.9.4 fails to properly verify front-end form submissions against the originally rendered form. This allows unauthenticated remote attackers to submit data against arbitrary registered forms and modify bound post titles and content. The flaw exposes content integrity risks on affected WordPress sites.

Description

The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.

Impact

The vulnerability primarily impacts the integrity of WordPress posts bound to front-end forms, allowing unauthorized modifications by unauthenticated users. Confidentiality and availability impacts are negligible, but data tampering is a concern for affected organizations. Content administrators and site owners face potential defacement or unauthorized data injection.

Remediation

Update the Secure Custom Fields WordPress plugin to version 6.9.4 or later immediately. Ensure that all third-party plugins are regularly monitored for security updates and maintain robust backup procedures for site content.

Risk context

The vulnerability is rated as low severity with a CVSS v3 score of 3.7 and a very low EPSS score of 0.00136, indicating minimal active exploitation in the wild. While urgency is low, routine patching is recommended to maintain defense-in-depth.

Affected products

  • Secure Custom Fields WordPress plugin

Scores

Severity
low
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
EPSS
0.00136

wordpress plugin unauthenticated data-integrity low-severity

← All CVEs