Custom Field Suite

Custom Field Suite has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2024; 5 are fixed and 4 remain unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 6 disclosures.

The most common weakness is Cross-Site Scripting, behind 6 of the records (67%). Other recurring categories include Eval Injection, Improper Authorization.

5 of the records (56%) have a vendor fix, while 4 remain unpatched. The oldest unresolved one dates back to 2024.

6 independent researchers contributed these findings, most of them (4) reported by Jack Taylor.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage56%
Open

4

Fixed

5

Get automatic notifications for all Custom Field Suite vulnerabilities before they are exploited.

Most severe open issueCVSS 8.8CVE-2024-3562

Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) PHP Code Injection via Loop Custom Field

Read the full analysis

Vulnerability Records

9 records
2024-06-19 13:17CVE-2024-3558
6.4
Medium
Jack TaylorNo
2024-06-19 13:10CVE-2024-3562
8.8
High
Jack TaylorNo
2024-06-19 13:02CVE-2024-3561
8.8
High
Jack TaylorNo
2024-06-11 16:19CVE-2024-3559
6.4
Medium
Jack TaylorNo
2024-05-07 00:00CVE-2024-3068
4.4
Medium
Eduardo Berlanga (seqode)Yes
2024-02-28 00:00CVE-2024-0689
4.4
Medium
catfatherYes
2023-05-10 00:00CVE-2023-32515
4.4
Medium
Taihei ShimamineYes
2019-05-08 00:00CVE-2019-11871
5.4
Medium
reddy.ioYes
2015-03-12 00:00N/A
6.3
Medium
James GolovichYes
Showing 1–9 of 9 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C