VYPR

Smart Custom Fields

by WordPress

Source repositories

CVEs (3)

  • CVE-2025-22308MedJan 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Kitajima Smart Custom Fields smart-custom-fields allows Stored XSS.This issue affects Smart Custom Fields: from n/a through <= 5.0.0.

  • CVE-2026-4066MedMar 23, 2026
    risk 0.28cvss 4.3epss 0.00

    The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with…

  • CVE-2024-1995MedMar 20, 2024
    risk 0.21cvss 4.3epss 0.01

    The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 4.2.2. This makes it possible for authenticated attackers, with…