Smart Custom Fields

Smart Custom Fields has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 4 issues recorded for Smart Custom Fields has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, one record each. Smart Custom Fields is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Smart Custom Fields vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2026-2594

Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title

Read the full analysis

Vulnerability Records

4 records
Smart Custom Fields banner
Latestv5.0.8

Smart Custom Fields

Takashi Kitajima

Author

Takashi Kitajima

4.9(20)
98/100
Last Updated
2026-07-16 (2mo ago)
Active Installs
50,000+
Downloads
379,020
Requires WP
6.4+
Requires PHP
7.4+
Tested up to
WP 6.8.8
Created
2014-10-09 (12y ago)

Smart Custom Fields is a simple plugin for managing custom fields. Features Field group loop support. Meta data revision support. Meta data preview support. Field Types Text Textarea Radio Select Checkbox WYSIWYG editor Image File Related Posts Related Terms Color picker Date picker Datetime picker Boolean Message How to get meta data ? **The return value of each of the following methods is not sanitized. Please sanitize them if necessary. ** https://developer.wordpress.org/apis/security/escaping/ Post meta data This method can get any meta data. SCF::get( 'field-name' ) This method can get meta data of any group. SCF::get( 'group-name' ) This method can get all meta data. SCF::gets() User meta data This method can get any user meta data. SCF::get_user_meta( $user_id, 'field-name' ) This method can get user meta data of any group. SCF::get_user_meta( $user_id, 'group-name' ) This method can get all user meta data. SCF::get_user_meta( $user_id ) Term meta data This method can get any term meta data. SCF::get_term_meta( $term_id, $taxonomy 'field-name' ) This method can get term meta data of any group. SCF::get_term_meta( $term_id, $taxonomy, 'group-name' ) This method can get all term meta data. SCF::get_term_meta( $term_id, $taxonomy ) Custom options page meta data This method can get any custom options page meta data. SCF::get_option_meta( $menu_slug, 'field-name' ) This method can get custom options page meta data of any group. SCF::get_option_meta( $menu_slug, 'group-name' ) This method can get all custom options page meta data. SCF::get_option_meta( $menu_slug ) Create custom options page SCF::add_options_page( $page_title, $menu_title, $capability, $menu_slug, $icon_url = '', $position = null ); Register custom fields by the code. .gist table { margin-bottom: 0; } This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters Show hidden characters <?php /** * カスタムフィールドを定義 * * @param array $settings Smart_Custom_Fields_Setting オブジェクトの配列 * @param string $type 投稿タイプ or ロール * @param int $id 投稿ID or ユーザーID * @param string $meta_type post | user * @return array */ function my_register_fields( $settings, $type, $id, $meta_type ) { // SCF::add_setting( 'ユニークなID', 'メタボックスのタイトル' ); $Setting = SCF::add_setting( 'id-1', 'functions.php から追加 その1' ); // $Setting->add_group( 'ユニークなID', 繰り返し可能か, カスタムフィールドの配列 ); $Setting->add_group( 'group-name-1', false, array( array( 'name' => 'field-1', 'label' => 'テストフィールド', 'type' => 'text', ), array( 'name' => 'field-2', 'label' => 'テストフィール2', 'type' => 'text', 'default' => 2, ), ) ); $settings[] = $Setting; return $settings; } add_filter( 'smart-cf-register-fields', 'my_register_fields', 10, 4 ); view raw gistfile1.php hosted with &#10084; by GitHub GitHub https://github.com/inc2734/smart-custom-fields/ Translators Japanese(ja) – JOTAKI Taisuke You can translate this plugin into your language by using GlotPress.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C