{"id":"CVE-2026-92403","published":"2026-09-19T07:16:33.683","lastModified":"2026-09-21T13:34:57.127","description":"The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.","cvssScore":3.7,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/740341ca-6419-4980-8ee9-d9e5c0f8df92/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}