Executive brief
The Custom Field Template plugin for WordPress contains a SQL injection vulnerability that allows authenticated contributors to extract sensitive data from the WordPress database. An attacker with contributor-level permissions can bypass capability checks by exploiting how WordPress casts the post_ID parameter, potentially exposing user information, posts, and other database contents without administrative approval.
Technical details
The plugin fails to properly sanitize and escape the 'post_ID' parameter before using it in SQL queries. Although the plugin checks edit_post permissions using current_user_can('edit_post', $id), WordPress internally casts the $id to an integer for this check while preserving the original unsanitized string for the SQL sink. Authenticated attackers with contributor-level access can append arbitrary SQL queries by leveraging a valid nonce obtainable from the post edit screen, bypassing the intended permission model.
Affected products
- Kabuto Inc. Custom Field Template up to and including 2.7.8
Timeline
- 2026-09-19: disclosed