Impact
The Secure Custom Fields WordPress plugin before version 6.9.4 allows the front‑end form submission to be accepted without confirming that the form ID matches the originally rendered form. Because this verification step is omitted, an unauthenticated user can replace the form ID in the request payload with the ID of any other registered form and directly change the title and content of the post that the targeted form is bound to. This flaw can lead to defacement, content tampering, or the insertion of malicious text that compromises the integrity of the website.
Affected Systems
WordPress sites that have installed the Secure Custom Fields plugin and are running any version earlier than 6.9.4. Any instance where the front‑end form feature is enabled is potentially vulnerable.
Risk and Exploitability
An attacker can exploit this issue by sending a crafted form submission from an unauthenticated client, as no authentication is required to reach the vulnerable endpoint. The CVSS base score of 3.7 reflects a low to moderate severity, and the EPSS score of less than 1% indicates that the probability of exploitation observed in the field is very low. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment