CVE-2026-92403: Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-End Form ID Substitution
Published Sep 19, 2026
·Updated
The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.
Affected Software
1 affected component
WordPress Secure Custom Fields<6.9.4
Event History
Sep 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Does exploitation require a WordPress account or authentication?
No. The issue can be exploited by unauthenticated users through a front-end form submission.
2
What must an attacker be able to do to exploit this issue?
They need to submit a front-end form while substituting the form ID with that of a different registered form. The substituted form must be bound to the post whose title and content they intend to modify.
3
Which plugin versions are affected?
Secure Custom Fields versions before 6.9.4 are affected.