Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Custom Field Template — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Custom Field Template, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the Custom Field Template product, categorized under the weakness type of improper input validation and configuration management within the vendor's ecosystem. The collection encompasses a comprehensive range of security flaws, including cross-site scripting, privilege escalation, and information disclosure incidents that have been publicly disclosed or verified by trusted security researchers. This database covers vulnerability reports spanning from the initial release of the software through the most recent patches, ensuring a complete historical context for the identified issues. By navigating this aggregated view, users can efficiently track a vendor’s advisory history to understand the pace and nature of security improvements over time. Visitors can also gain a deeper understanding of specific weakness classes as they manifest in real-world applications, observing how theoretical vulnerabilities translate into practical exploits or misconfigurations. Furthermore, the page serves as a detailed lookup tool for examining a product’s complete vulnerability history, allowing administrators and security analysts to assess risk exposure, review patch notes, and make informed decisions about upgrade paths. This resource is designed to provide clarity and transparency regarding the security posture of Custom Field Template, facilitating better threat management and compliance reporting without overwhelming the user with redundant or unverified data points. The structured presentation enables quick reference for specific threat categories while maintaining an overview of the overall security landscape associated with this particular software component.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2025-68607 WordPress Custom Field Template plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-12-29
CVE-2025-63058 WordPress Custom Field Template plugin <= 2.7.6 - Sensitive Data Exposure vulnerability CWE-497 4.3 Medium2025-12-09
CVE-2024-44062 WordPress Custom Field Template plugin <= 2.6.5 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-09-15
CVE-2024-0653 Custom Field Template <= 2.6.1 - Authenticated (Admin+) Stored Cross-Site Scritping CWE-79 4.4 Medium2024-06-11
CVE-2023-6748 Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Information Exposure CWE-862 4.3 Medium2024-06-11
CVE-2024-0627 Custom Field Template <= 2.6.1 - Authenticated(Constibutor+) Stored Cross-Site Scripting via Custom Field Name CWE-79 6.4 Medium2024-06-11
CVE-2023-6745 Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode CWE-79 6.4 Medium2024-06-11
CVE-2024-25919 WordPress Custom Field Template plugin <= 2.6 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-03-15
CVE-2023-38392 WordPress Custom Field Template Plugin <= 2.5.9 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High2023-08-07
CVE-2023-22695 WordPress Custom Field Template Plugin <= 2.5.8 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-07-10
CVE-2020-36742 Custom Field Template <= 2.5.1 - Cross-Site Request Forgery Bypass CWE-352 4.3 Medium2023-07-01
CVE-2022-4324 Custom Field Template < 2.5.8 - Admin+ PHP Object Injection 7.2 -2023-01-02

All 12 known CVE vulnerabilities affecting Custom Field Template with full Chinese analysis, references, and POCs where available.