SQL Injection Vulnerability in Custom Field Template by WordPress
CVE-2026-57687
8.5HIGH
What is CVE-2026-57687?
The Custom Field Template plugin for WordPress versions up to 2.7.8 is vulnerable to SQL injection attacks. This issue allows an attacker to manipulate SQL queries through unsanitized data inputs, potentially leading to unauthorized access to the database, data leakage, or corruption.
Affected Version(s)
Custom Field Template <= 2.7.8