CVE-2026-92403 PUBLISHED

Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-End Form ID Substitution

Assigner: WPScan
Reserved: 16.09.2026 Published: 19.09.2026 Updated: 19.09.2026

The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.

Product Status

Vendor Unknown
Product Secure Custom Fields
Versions Default: unaffected
  • affected from 0 to 6.9.4 (excl.)

Credits

  • Charles Vosburgh finder
  • WPScan coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE