First published: Mon Feb 05 2024(Updated: )
The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possible for authenticated attackers with contributor-level and above permissions to call arbitrary functions and execute code.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | <1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6996 is considered a critical vulnerability due to its potential for code injection.
To fix CVE-2023-6996, update the Display Custom Fields in the Frontend – Post and User Profile Fields plugin to version 1.3.0 or higher.
CVE-2023-6996 allows attackers to inject malicious code through the vg_display_data shortcode, compromising site security.
If you are using the Display Custom Fields in the Frontend – Post and User Profile Fields plugin version 1.2.1 or earlier, your site is vulnerable to CVE-2023-6996.
CVE-2023-6996 affects all versions of the Display Custom Fields in the Frontend plugin up to and including version 1.2.1.