Stored Cross-Site Scripting in Smart Custom Fields Plugin by Patchstack
CVE-2025-22308
6.5MEDIUM
Summary
The Smart Custom Fields plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting (XSS). This occurs due to improper handling of user inputs during web page generation, enabling attackers to inject malicious scripts into content that is later viewed by users. This vulnerability impacts versions from 'n/a' through 5.0.0, making it crucial for users to update their installations to mitigate potential exploitation.
Affected Version(s)
Smart Custom Fields <= 5.0.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Robert DeVore (Patchstack Alliance)