PT-2024-26570 · WordPress · Custom Field Suite

Jack Taylor

·

Published

2024-06-20

·

Updated

2024-07-15

·

CVE-2024-3562

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Custom Field Suite plugin for WordPress versions up to, and including, 2.6.7
Description The issue is related to insufficient sanitization of input prior to being used in a call to the eval() function, which makes it possible for authenticated attackers, with contributor-level access and above, to execute arbitrary PHP code on the server. This is achieved via the Loop custom field.
Recommendations For versions up to, and including, 2.6.7, update to a version that fixes the PHP Code Injection issue to prevent authenticated attackers from executing arbitrary PHP code on the server. As a temporary workaround, consider restricting access to the Loop custom field to minimize the risk of exploitation.

Fix

Code Injection

Eval Injection

Weakness Enumeration

Related Identifiers

CVE-2024-3562

Affected Products

Custom Field Suite