← WordPress Vulnerabilities
WordPress security by component

Display custom fields in the frontend – Post and User Profile Fields

Display custom fields in the frontend – Post and User Profile Fields is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Feb 05, 2024; the highest CVE/CNA score is 8.8.

Plugin slug: display-custom-fields-in-the-frontend-post-and-user-profile-fields

CVE-2023-6996: Display custom fields in the frontend – Post and User Profile Fields: Code execution

Display custom fields in the frontend – Post and User Profile Fields is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.

PublishedFeb 05, 2024
Safe version guidanceSee mitigation notes
Safe version
Feb 05, 2024 CVE-2023-6996
Display custom fields in the frontend – Post and User Profile Fields: Code execution
Display custom fields in the frontend – Post and User Profile Fields is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVD8.8
Feb 05, 2024 CVE-2023-6983
Display custom fields in the frontend – Post and User Profile Fields: A security weakness
Display custom fields in the frontend – Post and User Profile Fields is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Feb 05, 2024 CVE-2023-6982
Display custom fields in the frontend – Post and User Profile Fields: Cross-site scripting
Display custom fields in the frontend – Post and User Profile Fields is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4