CVE-2026-9855 - Custom Field Template = 2.7.8 - Authenticated (Contributor+) SQL Injection via 'post_ID' Parameter
Brief
CVE ID : CVE-2026-9855
Published : Sept. 19, 2026, 8:16 a. m.
- 12 hours, 40 minutes ago
Description : The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.
- 8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
