Stored Cross-Site Scripting Vulnerability in Smart Custom Fields Plugin for WordPress
CVE-2026-2594
6.4MEDIUM
What is CVE-2026-2594?
The Smart Custom Fields plugin for WordPress is affected by a stored cross-site scripting (XSS) vulnerability in versions up to 5.0.7. This security issue arises from inadequate sanitization of user input and improper escaping of output in image attachment titles. Authenticated attackers with Author-level access or higher can exploit this flaw to embed malicious scripts within the uploaded titles. These scripts will execute when legitimate users access pages containing the injected content, potentially compromising user sessions and site integrity. A partial patch was introduced in version 5.0.7, but users are advised to monitor updates for comprehensive fixes.
Affected Version(s)
Smart Custom Fields 0 <= 5.0.7