Stored XSS Vulnerability in Custom Field Template by Hiroaki Miyashita
CVE-2025-68607

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 December 2025

What is CVE-2025-68607?

A Cross-site Scripting (XSS) vulnerability has been identified in the Custom Field Template plugin developed by Hiroaki Miyashita. This flaw allows attackers to inject malicious scripts into web pages that may be executed when users view the affected pages. The vulnerability impacts versions n/a through 2.7.5, posing a security risk for WordPress websites using this plugin. Proper sanitization of user inputs is crucial to mitigate this risk and protect against potential exploitation.

Affected Version(s)

Custom Field Template <= 2.7.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ | Patchstack Bug Bounty Program
.