Vulnerabilities (CVE)

Filtered by vendor Bestwebsoft Subscribe
Filtered by product Profile Extra Fields
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-4469 1 Bestwebsoft 1 Profile Extra Fields 2024-02-28 N/A 5.3 MEDIUM
The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to expose potentially sensitive user data, including data entered into custom fields.