Where is the CVE? What risk is there continuing to use the original plugin? No details at all. This results in fear: we don't know if the original is safe to use.
> Going forward, Secure Custom Fields is now a non-commercial plugin
Does this imply that Wordpress is potentially going after a revenue stream from WPEngine?
If the plugin had Pro options* then are those closed source and so not available to Wordpress in their fork of the codebase? It's not clear.