CVE-2026-92403
Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-End Form ID Substitution
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.
| Vendor | unknown |
| Product | secure custom fields |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown secure custom fields
Be the first to know when new unknown vulnerabilities affecting unknown secure custom fields are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Secure Custom Fields
0 < 6.9.4
References
Credits
Charles Vosburgh WPScan