Access violation vulnerability in Custom Field Suite 2.4

The Custom Field Suite plugin for WordPress is a tool that allows users to easily create custom fields for their website. Unfortunately, in versions up to and including 2.4.1, there is a security vulnerability that could allow unauthorized attackers to access and execute restricted AJAX actions, such as importing and exporting custom fields. This is due to missing capability checks in the ajax_handler() function.

Detected in:

Custom Field Suite open vulnerable versions: >= * <= 2.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.