plugin

Shortcode To Display Post And User Data Vulnerabilities

8 known security issues reported for the Shortcode To Display Post And User Data WordPress plugin. Most recent disclosed Dec 9, 2024.

1 high 3 medium

Running Shortcode To Display Post And User Data on your site? Check whether your installed version is affected.

Scan your site free

Display custom fields in the frontend &#8211; Post and User Profile Fields [shortcode-to-display-post-and-user-data] < 1.2.1

unknown

[en] Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0.

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Dec 9, 2024

CVE-2023-31073 on NVD →

Display custom fields in the frontend &#8211; Post and User Profile Fields [shortcode-to-display-post-and-user-data] < 1.3.0

unknown

[en] The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and postmeta in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This...

Affected:
up to 1.3.0
Fixed in:
1.3.0
Disclosed:
Feb 5, 2024

CVE-2023-6982 on NVD →

Display custom fields in the frontend &#8211; Post and User Profile Fields [shortcode-to-display-post-and-user-data] < 1.3.0

unknown

[en] The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possib...

Affected:
up to 1.3.0
Fixed in:
1.3.0
Disclosed:
Feb 5, 2024

CVE-2023-6996 on NVD →

Display custom fields in the frontend &#8211; Post and User Profile Fields [shortcode-to-display-post-and-user-data] < 1.3.0

unknown

[en] The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing validation on a user controlled key. This makes it possible for authenticated...

Affected:
up to 1.3.0
Fixed in:
1.3.0
Disclosed:
Feb 5, 2024

CVE-2023-6983 on NVD →

Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Code Injection

high

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possible fo...

CVSS:
8.8
Affected:
up to 1.2.1
Fixed in:
1.3.0
Disclosed:
Jan 16, 2024

CVE-2023-6996 on NVD →

Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via vg_display_data

medium

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and postmeta in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This make...

CVSS:
6.4
Affected:
up to 1.2.1
Fixed in:
1.3.0
Disclosed:
Jan 16, 2024

CVE-2023-6982 on NVD →

Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Meta Disclosure

medium

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attac...

CVSS:
4.3
Affected:
up to 1.2.1
Fixed in:
1.3.0
Disclosed:
Jan 16, 2024

CVE-2023-6983 on NVD →

Display custom fields in the frontend – Post and User Profile Fields <= 1.2.0 - Missing Authorization via vg_display_data shortcode

medium

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the display_object_data_shortcode function referenced by the vg_display_data shortcode in versions up to, and including, 1.2.0. This makes it po...

CVSS:
6.5
Affected:
up to 1.2.0
Fixed in:
1.2.1
Disclosed:
Apr 24, 2023

CVE-2023-31073 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database