Custom Field Suite Project maintains a narrowly scoped WordPress plugin that provides custom field management functionality and sits within a large ecosystem of WordPress sites, giving it notable reach despite modest CVE volume. Its vulnerabilities center on input-handling and code-execution weaknesses—cross-site scripting, code injection, eval injection, and SQL injection—that are characteristic of web application plugins where user-controlled data flows into dynamic code generation and database queries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Custom Field Suite Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3562HIGH The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient s | Jun 20, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-3561HIGH The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 due to insufficient escaping | Jun 20, 2024 | 8.8 | 25 | NO | NO |
CVE-2019-11871MEDIUM The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins. | May 10, 2019 | 5.4 | 20 | NO | NO |
CVE-2023-32515MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions. | May 18, 2023 | 4.8 | 19 | NO | NO |
CVE-2024-3558MEDIUM The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and including, 2.6.7 due to insuffi | Jun 20, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-3559MEDIUM The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insuf | Jun 12, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-3068MEDIUM The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to | May 14, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-0689MEDIUM The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up to, and including, 2.6.4 due to insufficient input san | Feb 29, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Custom Field Suite Project.
Media articles that mention a CVE ID that affects a product developed by Custom Field Suite Project — matched by CVE ID, not by vendor name.