CVE-2026-12995

CVE-2026-12995 published: The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key. This makes it possible for authenticated...

View full NVD advisory → ← Back to CVE watch