Junglewise Threat Intelligence

CVE-2026-57687: Hiroaki Miyashita Custom Field Template SQL Injection

CVE-2026-57687 · Severity: high · CVSS 8.5 · Published 2026-07-02

Executive brief

The Custom Field Template plugin for WordPress, which allows administrators to manage custom data fields for posts and pages, contains a security vulnerability. An attacker with basic contributor-level access to the website could exploit this flaw to interact directly with the site's database. This could lead to the unauthorized theft of sensitive information or disruption of site operations.

Technical details

A SQL Injection vulnerability exists in the Custom Field Template plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 2.7.8. An authenticated attacker with 'Contributor' permissions or higher can exploit this via the network to execute arbitrary SQL queries against the backend database. This could result in unauthorized data exfiltration or limited impact on database availability. The issue has been addressed in version 2.8.

Affected products

  • Hiroaki Miyashita Custom Field Template <= 2.7.8

Timeline

  • 2026-02-28: disclosed: Reported by daroo
  • 2026-06-29: advisory: Published by Patchstack
  • 2026-06-29: patched: Version 2.8 released
  • 2026-07-02: advisory: NVD published CVE-2026-57687

References