VYPR

User Extra Fields

by vanquish

CVEs (2)

  • CVE-2024-11150CriNov 13, 2024
    risk 0.64cvss 9.8epss 0.01

    The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 16.6. This makes it possible for unauthenticated attackers to…

  • CVE-2024-10800HigNov 13, 2024
    risk 0.57cvss 8.8epss 0.01

    The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields() function in all versions up to, and including, 16.6. This makes it possible for authenticated attackers, with subscriber-level…