The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. This makes it possible for authenticated attackers with contributor access and above, to extract sensitive data including arbitrary post metadata.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jan 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpgogo
Wpgogo custom Field Template |
|
Weaknesses | CWE-922 | |
CPEs | cpe:2.3:a:wpgogo:custom_field_template:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpgogo
Wpgogo custom Field Template |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-02T08:42:07.349Z
Reserved: 2023-12-12T17:57:37.948Z
Link: CVE-2023-6748

Updated: 2024-08-02T08:42:07.349Z

Status : Analyzed
Published: 2024-06-11T03:15:09.310
Modified: 2025-01-29T17:53:06.850
Link: CVE-2023-6748

No data.