Smart Custom Fields
Smart Custom Fields has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 4 issues recorded for Smart Custom Fields has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, one record each. Smart Custom Fields is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2026-2594Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
Read the full analysisVulnerability Records

Smart Custom Fields
Author
Takashi Kitajima
Smart Custom Fields is a simple plugin for managing custom fields. Features Field group loop support. Meta data revision support. Meta data preview support. Field Types Text Textarea Radio Select Checkbox WYSIWYG editor Image File Related Posts Related Terms Color picker Date picker Datetime picker Boolean Message How to get meta data ? **The return value of each of the following methods is not sanitized. Please sanitize them if necessary. ** https://developer.wordpress.org/apis/security/escaping/ Post meta data This method can get any meta data. SCF::get( 'field-name' ) This method can get meta data of any group. SCF::get( 'group-name' ) This method can get all meta data. SCF::gets() User meta data This method can get any user meta data. SCF::get_user_meta( $user_id, 'field-name' ) This method can get user meta data of any group. SCF::get_user_meta( $user_id, 'group-name' ) This method can get all user meta data. SCF::get_user_meta( $user_id ) Term meta data This method can get any term meta data. SCF::get_term_meta( $term_id, $taxonomy 'field-name' ) This method can get term meta data of any group. SCF::get_term_meta( $term_id, $taxonomy, 'group-name' ) This method can get all term meta data. SCF::get_term_meta( $term_id, $taxonomy ) Custom options page meta data This method can get any custom options page meta data. SCF::get_option_meta( $menu_slug, 'field-name' ) This method can get custom options page meta data of any group. SCF::get_option_meta( $menu_slug, 'group-name' ) This method can get all custom options page meta data. SCF::get_option_meta( $menu_slug ) Create custom options page SCF::add_options_page( $page_title, $menu_title, $capability, $menu_slug, $icon_url = '', $position = null ); Register custom fields by the code. .gist table { margin-bottom: 0; } This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters Show hidden characters <?php /** * カスタムフィールドを定義 * * @param array $settings Smart_Custom_Fields_Setting オブジェクトの配列 * @param string $type 投稿タイプ or ロール * @param int $id 投稿ID or ユーザーID * @param string $meta_type post | user * @return array */ function my_register_fields( $settings, $type, $id, $meta_type ) { // SCF::add_setting( 'ユニークなID', 'メタボックスのタイトル' ); $Setting = SCF::add_setting( 'id-1', 'functions.php から追加 その1' ); // $Setting->add_group( 'ユニークなID', 繰り返し可能か, カスタムフィールドの配列 ); $Setting->add_group( 'group-name-1', false, array( array( 'name' => 'field-1', 'label' => 'テストフィールド', 'type' => 'text', ), array( 'name' => 'field-2', 'label' => 'テストフィール2', 'type' => 'text', 'default' => 2, ), ) ); $settings[] = $Setting; return $settings; } add_filter( 'smart-cf-register-fields', 'my_register_fields', 10, 4 ); view raw gistfile1.php hosted with ❤ by GitHub GitHub https://github.com/inc2734/smart-custom-fields/ Translators Japanese(ja) – JOTAKI Taisuke You can translate this plugin into your language by using GlotPress.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C