Custom Field Suite Project

Custom Field Suite

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.13%
  • Veröffentlicht 20.06.2024 02:15:10
  • Zuletzt bearbeitet 21.11.2024 09:29:52

The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the eval() funct...

Exploit
  • EPSS 0.89%
  • Veröffentlicht 20.06.2024 02:15:09
  • Zuletzt bearbeitet 21.11.2024 09:29:52

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible f...

  • EPSS 0.98%
  • Veröffentlicht 20.06.2024 02:15:09
  • Zuletzt bearbeitet 21.11.2024 09:29:52

The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...

  • EPSS 0.36%
  • Veröffentlicht 12.06.2024 05:15:49
  • Zuletzt bearbeitet 05.02.2025 14:59:43

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible...

  • EPSS 0.5%
  • Veröffentlicht 14.05.2024 15:39:52
  • Zuletzt bearbeitet 03.02.2025 18:45:24

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it po...

  • EPSS 0.2%
  • Veröffentlicht 29.02.2024 03:15:06
  • Zuletzt bearbeitet 05.02.2025 18:11:53

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the meta values. This makes it possib...

  • EPSS 0.08%
  • Veröffentlicht 18.05.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 08:03:30

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions.

  • EPSS 0.27%
  • Veröffentlicht 10.05.2019 03:29:01
  • Zuletzt bearbeitet 21.11.2024 04:21:55

The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.