0
I Use This!
Very Low Activity
Analyzed about 6 hours ago. based on code collected 1 day ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2024-3562 BDSA-2024-3865 High Jun 20, 2024 The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. more...
2.6.7, 2.6.5, 2.6.4, 2.6.2.1, 2.6.2, 2.6, 2.5.16, 2.5.15, 2.5.14, 2.5.13
CVE-2024-3561 BDSA-2024-3869 High Jun 20, 2024 The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 more...
2.6.7, 2.6.5, 2.6.4, 2.6.2.1, 2.6.2, 2.6, 2.5.16, 2.5.15, 2.5.14, 2.5.13
CVE-2024-3559 BDSA-2024-3891 Medium Jun 12, 2024 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and more...
2.6.7, 2.6.5, 2.6.4, 2.6.2.1, 2.6.2, 2.6, 2.5.16, 2.5.15, 2.5.14, 2.5.13
CVE-2024-3558 BDSA-2024-3870 Medium Jun 20, 2024 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and in more...
2.6.7, 2.6.5, 2.6.4, 2.6.2.1, 2.6.2, 2.6, 2.5.16, 2.5.15, 2.5.14, 2.5.13