Impact
The Smart Custom Fields plugin for WordPress stores the title of uploaded images without proper sanitization or escaping. This allows an authenticated attacker with Author or higher privileges to inject malicious JavaScript into the title field, which is then rendered on any page that displays the attachment, enabling client‑side code execution and potential cookie theft, session hijacking, or defacement.
Affected Systems
WordPress installations that have the inc2734 Smart Custom Fields plugin at version 5.0.7 or earlier are affected. The vulnerability applies to all revisions up to and including 5.0.7, regardless of other plugins or themes installed.
Risk and Exploitability
The CVSS score of 6.4 labels this issue as moderate in overall severity. The EPSS score of less than 1% indicates that exploitation in the wild is currently unlikely. The vulnerability is not listed in CISA KEV. An attacker must first acquire Author‑level or higher credentials to upload an image with a malicious title; there is no known public exploit beyond the demonstrated functionality, so the risk remains limited under these constraints.
OpenCVE Enrichment