Impact
The Secure Custom Fields WordPress plugin before version 6.9.4 fails to verify that a front‑end form submission matches the form that was rendered to the visitor. This allows an unauthenticated user to replace the form ID with that of a different registered form and alter the title and content of the post bound to that form. Such unauthorized modification can lead to defacement or loss of legitimate content, compromising the integrity of the site.
Affected Systems
WordPress sites using the Secure Custom Fields plugin, versions prior to 6.9.4. Any installation that has enabled the front‑end form functionality is potentially vulnerable.
Risk and Exploitability
The vulnerability can be exploited by sending a crafted form submission from any client without authentication. No EPSS or KEV assignment is listed, but the absence of access controls combined with the ability to modify content suggests a high severity risk. Attackers could achieve arbitrary post changes by manipulating the form ID in the request payload.
OpenCVE Enrichment