Stored Cross-Site Scripting Vulnerability in Smart Custom Fields Plugin for WordPress
CVE-2026-2594

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 July 2026

What is CVE-2026-2594?

The Smart Custom Fields plugin for WordPress is affected by a stored cross-site scripting (XSS) vulnerability in versions up to 5.0.7. This security issue arises from inadequate sanitization of user input and improper escaping of output in image attachment titles. Authenticated attackers with Author-level access or higher can exploit this flaw to embed malicious scripts within the uploaded titles. These scripts will execute when legitimate users access pages containing the injected content, potentially compromising user sessions and site integrity. A partial patch was introduced in version 5.0.7, but users are advised to monitor updates for comprehensive fixes.

Affected Version(s)

Smart Custom Fields 0 <= 5.0.7

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lucsob
.