low · CVSS v3 3.7 · EPSS 0.00136
CVE-2026-92403
The Secure Custom Fields WordPress plugin before version 6.9.4 fails to properly verify front-end form submissions against the originally re
Overview
The Secure Custom Fields WordPress plugin before version 6.9.4 fails to properly verify front-end form submissions against the originally rendered form. This allows unauthenticated remote attackers to submit data against arbitrary registered forms and modify bound post titles and content. The flaw exposes content integrity risks on affected WordPress sites.
Description
The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.
Impact
The vulnerability primarily impacts the integrity of WordPress posts bound to front-end forms, allowing unauthorized modifications by unauthenticated users. Confidentiality and availability impacts are negligible, but data tampering is a concern for affected organizations. Content administrators and site owners face potential defacement or unauthorized data injection.
Remediation
Update the Secure Custom Fields WordPress plugin to version 6.9.4 or later immediately. Ensure that all third-party plugins are regularly monitored for security updates and maintain robust backup procedures for site content.
Risk context
The vulnerability is rated as low severity with a CVSS v3 score of 3.7 and a very low EPSS score of 0.00136, indicating minimal active exploitation in the wild. While urgency is low, routine patching is recommended to maintain defense-in-depth.
Affected products
- Secure Custom Fields WordPress plugin
Scores
- Severity
- low
- CVSS v2
- 2.6
- CVSS v3
- 3.7
- CVSS v4
- —
- EPSS
- 0.00136