Stored XSS Vulnerability in Custom Field Template by Hiroaki Miyashita
CVE-2025-68607
6.5MEDIUM
What is CVE-2025-68607?
A Cross-site Scripting (XSS) vulnerability has been identified in the Custom Field Template plugin developed by Hiroaki Miyashita. This flaw allows attackers to inject malicious scripts into web pages that may be executed when users view the affected pages. The vulnerability impacts versions n/a through 2.7.5, posing a security risk for WordPress websites using this plugin. Proper sanitization of user inputs is crucial to mitigate this risk and protect against potential exploitation.
Affected Version(s)
Custom Field Template <= 2.7.5
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Muhammad Yudha - DJ | Patchstack Bug Bounty Program