PT-2024-26570 · WordPress · Custom Field Suite
Jack Taylor
·
Published
2024-06-20
·
Updated
2024-07-15
·
CVE-2024-3562
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Custom Field Suite plugin for WordPress versions up to, and including, 2.6.7
Description
The issue is related to insufficient sanitization of input prior to being used in a call to the
eval() function, which makes it possible for authenticated attackers, with contributor-level access and above, to execute arbitrary PHP code on the server. This is achieved via the Loop custom field.Recommendations
For versions up to, and including, 2.6.7, update to a version that fixes the PHP Code Injection issue to prevent authenticated attackers from executing arbitrary PHP code on the server. As a temporary workaround, consider restricting access to the Loop custom field to minimize the risk of exploitation.
Fix
Code Injection
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Custom Field Suite