Description
The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.
Published: 2026-09-19
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Post Modification
Action: Patch Plugin
AI Analysis

Impact

The Secure Custom Fields WordPress plugin before version 6.9.4 allows the front‑end form submission to be accepted without confirming that the form ID matches the originally rendered form. Because this verification step is omitted, an unauthenticated user can replace the form ID in the request payload with the ID of any other registered form and directly change the title and content of the post that the targeted form is bound to. This flaw can lead to defacement, content tampering, or the insertion of malicious text that compromises the integrity of the website.

Affected Systems

WordPress sites that have installed the Secure Custom Fields plugin and are running any version earlier than 6.9.4. Any instance where the front‑end form feature is enabled is potentially vulnerable.

Risk and Exploitability

An attacker can exploit this issue by sending a crafted form submission from an unauthenticated client, as no authentication is required to reach the vulnerable endpoint. The CVSS base score of 3.7 reflects a low to moderate severity, and the EPSS score of less than 1% indicates that the probability of exploitation observed in the field is very low. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 00:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Secure Custom Fields to version 6.9.4 or later
  • Implement server‑side validation to ensure that the submitted form ID matches the form displayed to the visitor and that only authorized users can modify post content
  • If an upgrade is not immediately possible, disable front‑end form submissions or require user authentication before allowing form submissions

Generated by OpenCVE AI on September 20, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions secure Custom Fields
Vendors & Products Wordpress-extensions
Wordpress-extensions secure Custom Fields

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.
Title Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-End Form ID Substitution
References

Subscriptions

Wordpress-extensions Secure Custom Fields
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:17:56.222Z

Reserved: 2026-09-16T08:52:01.638Z

Link: CVE-2026-92403

cve-icon Vulnrichment

Updated: 2026-09-19T13:11:07.283Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:33.683

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-92403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:23Z

Weaknesses