CVE-2026-9855 | Custom Field Template Plugin up to 2.7.8 on WordPress current_user_can post_ID sql injection

SecurityVulns

A vulnerability was found in Custom Field Template Plugin up to 2.7.8 on WordPress. It has been rated as critical. The affected element is the function current_user_can. The manipulation of the argument post_ID leads to sql injection.

This vulnerability is uniquely identified as CVE-2026-9855. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More