---
id: CVE-2026-92403
title: >-
  The Secure Custom Fields WordPress plugin before 6.9.4 does not properly
  verify that a front-end form submission corresponds to the form that was
  rendered to the visitor, allowing unauthenticated users to submit against a
  different regis…
summary: >-
  The Secure Custom Fields WordPress plugin before 6.9.4 does not properly
  verify that a front-end form submission corresponds to the form that was
  rendered to the visitor, allowing unauthenticated users to submit against a
  different regis…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
product: Secure Custom Fields
affected:
  - secure_custom_fields < 6.9.4
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:34:57.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92403'
references:
  - url: 'https://wpscan.com/vulnerability/740341ca-6419-4980-8ee9-d9e5c0f8df92/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00249
epssPercentile: 0.14373
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:11:21.180656Z'
ingestedAt: '2026-09-19T06:59:13.116Z'
---

## Overview

The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
