Skip to content

Known CVE

Custom Field Manager WordPress - Cross-Site Scripting

Custom Field Manager WordPress plugin through 1.0 contains a reflected XSS caused by unsanitized and unescaped parameter output, letting attackers execute scripts against high privilege users such as admin, exploit requires crafted request.

CVE-2024-12873

Medium2024CVSS 6.1CWE-79

cve2024 · f1logic · custom-field-manager · authenticated · wordpress · wp · wp-plugin · xss

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website