Junglewise Threat Intelligence

CVE-2026-9855: Custom Field Template plugin SQL injection via post_ID

CVE-2026-9855 · Severity: medium · CVSS 6.5 · Published 2026-09-19

Executive brief

The Custom Field Template plugin for WordPress contains a SQL injection vulnerability that allows authenticated contributors to extract sensitive data from the WordPress database. An attacker with contributor-level permissions can bypass capability checks by exploiting how WordPress casts the post_ID parameter, potentially exposing user information, posts, and other database contents without administrative approval.

Technical details

The plugin fails to properly sanitize and escape the 'post_ID' parameter before using it in SQL queries. Although the plugin checks edit_post permissions using current_user_can('edit_post', $id), WordPress internally casts the $id to an integer for this check while preserving the original unsanitized string for the SQL sink. Authenticated attackers with contributor-level access can append arbitrary SQL queries by leveraging a valid nonce obtainable from the post edit screen, bypassing the intended permission model.

Affected products

  • Kabuto Inc. Custom Field Template up to and including 2.7.8

Timeline

  • 2026-09-19: disclosed

References