Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Custom Field Template — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Custom Field Template, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities for the Custom Field Template product, categorized under the weakness type associated with its specific implementation contexts. It aggregates security reports, advisories, and bug trackings from various vendors and independent researchers who have identified issues within this software component. The collection covers a broad historical time range, starting from the initial public disclosure of early flaws through to recent updates, ensuring that both legacy and current security concerns are accessible. By compiling these disparate sources, the page provides a centralized view of the threat landscape surrounding Custom Field Template. Readers can use this resource to track a vendor's advisories as they are released, allowing for timely patching and risk assessment. Furthermore, users can understand a specific weakness class by examining how it manifests in different scenarios and configurations within this product. The page also facilitates looking up a product's vulnerability history, offering insights into the frequency and severity of past incidents. This historical data helps organizations evaluate the long-term stability and security posture of the Custom Field Template. Rather than focusing on isolated incidents, the aggregated view highlights patterns in development and remediation efforts over time. This approach supports more informed decision-making for security teams and system administrators who rely on this tool. The information presented is structured to aid in both immediate response actions and long-term strategic planning for software maintenance.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-57687 WordPress Custom Field Template plugin <= 2.7.8 - SQL Injection vulnerability CWE-89 8.5 High2026-07-02
CVE-2025-68607 WordPress Custom Field Template plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-12-29
CVE-2025-63058 WordPress Custom Field Template plugin <= 2.7.6 - Sensitive Data Exposure vulnerability CWE-497 4.3 Medium2025-12-09
CVE-2024-44062 WordPress Custom Field Template plugin <= 2.6.5 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-09-15
CVE-2024-0653 Custom Field Template <= 2.6.1 - Authenticated (Admin+) Stored Cross-Site Scritping CWE-79 4.4 Medium2024-06-11
CVE-2023-6748 Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Information Exposure CWE-862 4.3 Medium2024-06-11
CVE-2024-0627 Custom Field Template <= 2.6.1 - Authenticated(Constibutor+) Stored Cross-Site Scripting via Custom Field Name CWE-79 6.4 Medium2024-06-11
CVE-2023-6745 Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode CWE-79 6.4 Medium2024-06-11
CVE-2024-25919 WordPress Custom Field Template plugin <= 2.6 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-03-15
CVE-2023-38392 WordPress Custom Field Template Plugin <= 2.5.9 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High2023-08-07
CVE-2023-22695 WordPress Custom Field Template Plugin <= 2.5.8 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-07-10
CVE-2020-36742 Custom Field Template <= 2.5.1 - Cross-Site Request Forgery Bypass CWE-352 4.3 Medium2023-07-01
CVE-2022-4324 Custom Field Template < 2.5.8 - Admin+ PHP Object Injection 7.2 -2023-01-02

All 13 known CVE vulnerabilities affecting Custom Field Template with full Chinese analysis, references, and POCs where available.