CVE-2026-4066 | inc2734 Smart Custom Fields Plugin up to 5.0.6 on WordPress relational_posts_search authorization (EUVD-2026-14618)
A vulnerability was found in inc2734 Smart Custom Fields Plugin up to 5.0.6 on WordPress and classified as problematic. Affected by this issue is the function relational_posts_search. The manipulation results in missing authorization.
This vulnerability is known as CVE-2026-4066. It is possible to launch the attack remotely. No exploit is available.