Impact
Custom Field Template for WordPress allows contributors and higher roles to trigger SQL injection through the post_ID parameter. The plugin fails to escape this user‑supplied value and does not prepare the surrounding SQL query, enabling an attacker to append additional statements. Permission checks are bypassed because WordPress internally casts the post ID to an integer for the capability test while the original, unsanitized string is still sent to the database engine. A valid nonce, obtainable from the post edit screen, enables the injection with no other surface needed.
Affected Systems
WordPress sites running Custom Field Template version 2.7.8 or earlier are impacted. The vulnerability is present in all releases up to and including 2.7.8; later versions are presumed fixed and are not affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, authenticated users with contributor or higher access can read sensitive database information, so the risk exists wherever such roles are assigned and the susceptible plugin version is active.
OpenCVE Enrichment