Stored Cross-Site Scripting in Smart Custom Fields Plugin by Patchstack
CVE-2025-22308
6.5MEDIUM
What is CVE-2025-22308?
The Smart Custom Fields plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting (XSS). This occurs due to improper handling of user inputs during web page generation, enabling attackers to inject malicious scripts into content that is later viewed by users. This vulnerability impacts versions from 'n/a' through 5.0.0, making it crucial for users to update their installations to mitigate potential exploitation.
Affected Version(s)
Smart Custom Fields <= 5.0.0