
Custom Field Template Security & Risk Analysis
wordpress.org/plugins/custom-field-templateThe Custom Field Template plugin extends the functionality of custom fields.
Is Custom Field Template Safe to Use in 2026?
Use With Caution
Score 67/100Custom Field Template has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "custom-field-template" plugin v2.7.7 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries and incorporating nonce and capability checks. The attack surface, while present with AJAX handlers and shortcodes, is reported as having no unprotected entry points, which is a significant strength. However, the static analysis reveals concerning signals, particularly the presence of a dangerous `unserialize` function without explicit safeguards mentioned, and a worrying 45% of outputs are not properly escaped, suggesting a potential for Cross-Site Scripting vulnerabilities. The taint analysis also indicates flows with unsanitized paths, though no critical or high severity issues were identified here.
The plugin's vulnerability history is a major concern. With 12 known CVEs, a significant number of which are medium severity, and one high-severity unpatched vulnerability, this indicates a pattern of past security weaknesses. The common vulnerability types, including Exposure of Sensitive Information, XSS, Missing Authorization, Deserialization, and CSRF, suggest recurring issues in input validation, authorization, and secure handling of data. The most recent vulnerability recorded in late 2025 further underscores the ongoing nature of these security challenges. While the plugin has strengths in its query handling and some authentication measures, the historical prevalence of vulnerabilities and specific code signals like unescaped output and the use of `unserialize` necessitate caution.
Key Concerns
- 1 unpatched high severity CVE
- 11 medium severity CVEs
- 45% of outputs not properly escaped
- Presence of 'unserialize' function
- 3 flows with unsanitized paths
Custom Field Template Security Vulnerabilities
CVEs by Year
Severity Breakdown
12 total CVEs
Custom Field Template <= 2.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Custom Field Template <= 2.7.6 - Authenticated (Subscriber+) Information Exposure
Custom Field Template <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
Custom Field Template <= 2.6.1 - Authenticated(Constibutor+) Stored Cross-Site Scripting via Custom Field Name
Custom Field Template <= 2.6.1 - Authenticated(Contributor+) Information Exposure
Custom Field Template <= 2.6.1 - Authenticated (Admin+) Stored Cross-Site Scritping
Custom Field Template <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via $search_label
Custom Field Template <= 2.5.9 - Reflected Cross-Site Scripting
Custom Field Template <= 2.5.8 - Cross-Site Request Forgery via Plugin Options Update
Custom Field Template <= 2.5.7 - Authenticated (Administrator+) PHP Object Injection
Custom Field Template <= 2.5.1 - Cross-Site Request Forgery Bypass
Custom Field Template Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom Field Template Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 39
Scheduled Events 1
Maintenance & Trust
Custom Field Template Maintenance & Trust
Maintenance Signals
Community Trust
Custom Field Template Alternatives
Zen Custom Fields
zen-custom-fields
Easy to implement and use custom fields for WordPress templates.
Easy Architect
easy-architect
Visually build custom post types, meta fields, and dynamic templates—no code. Extended blocks for icons, galleries, embeds, and dynamic content.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
Custom Field Template Developer Profile
12 plugins · 43K total installs
How We Detect Custom Field Template
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-field-template/js/jquery.datetimepicker.js/wp-content/plugins/custom-field-template/js/jquery.dateformat.js/wp-content/plugins/custom-field-template/js/jquery.colorbox-min.js/wp-content/plugins/custom-field-template/js/jquery.min.js/wp-content/plugins/custom-field-template/js/jquery-ui.min.js/wp-content/plugins/custom-field-template/js/select2.min.js/wp-content/plugins/custom-field-template/js/select2_locale_ru.js/wp-content/plugins/custom-field-template/js/select2_locale_es.js+8 more/wp-content/plugins/custom-field-template/js/jquery.datetimepicker.js/wp-content/plugins/custom-field-template/js/jquery.dateformat.js/wp-content/plugins/custom-field-template/js/jquery.colorbox-min.js/wp-content/plugins/custom-field-template/js/jquery.min.js/wp-content/plugins/custom-field-template/js/jquery-ui.min.js/wp-content/plugins/custom-field-template/js/select2.min.js+5 morecustom-field-template/js/jquery.datetimepicker.js?ver=custom-field-template/js/jquery.dateformat.js?ver=custom-field-template/js/jquery.colorbox-min.js?ver=custom-field-template/js/jquery.min.js?ver=custom-field-template/js/jquery-ui.min.js?ver=custom-field-template/js/select2.min.js?ver=custom-field-template/js/select2_locale_ru.js?ver=custom-field-template/js/select2_locale_es.js?ver=custom-field-template/js/select2_locale_fr.js?ver=custom-field-template/js/select2_locale_de.js?ver=custom-field-template/js/custom_field_template.js?ver=custom-field-template/css/custom_field_template_admin.css?ver=custom-field-template/css/colorbox.css?ver=custom-field-template/css/select2.css?ver=custom-field-template/css/jquery-ui.css?ver=custom-field-template/css/jquery.datetimepicker.css?ver=HTML / DOM Fingerprints
cft_admin_noticescft_admin_add_formcft_field_rowcft_field_labelcft_field_inputcft_field_optionscft_field_delcft_field_id+112 moreThis program is based on the rc:custom_field_gui plugin written by Joshua Sigar.I appreciate your efforts, Joshua.Copyright 2008 - 2026 Hiroaki MiyashitaThis program is free software; you can redistribute it and/or modify+10 moredata-field-typedata-field-iddata-field-namedata-optionsdata-cft-idcustom_field_template_params[cft][cftsearch]