Medium 6.5
2025-12-30< 2.7.8
WordPress Custom Field Template plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability
Minimum safe version
2.7.8
Update to 2.7.8 or later to address 16 fixable vulnerabilities
WordPress Custom Field Template plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability
CVE-2025-63058
CVE-2024-44062
CVE-2024-0627
CVE-2023-6748
CVE-2024-0653
CVE-2023-6745
CVE-2024-25919
CVE-2023-38392
CVE-2020-36742
CVE-2021-4342
CVE-2023-22695
WordPress Custom Field Template Plugin < 2.5.8 is vulnerable to PHP Object Injection
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF)
WordPress Custom Field Template plugin <= 2.5.1 - Cross-Site Request Forgery (CSRF) vulnerability