๐Ÿ” CVE Alert

CVE-2023-4469

MEDIUM 5.3

Profile Extra Fields by BestWebSoft <= 1.2.7 - Missing Authorization to Sensitive Information Exposure

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to expose potentially sensitive user data, including data entered into custom fields.

CWE CWE-862
Vendor bestwebsoft
Product profile extra fields by bestwebsoft
Published Oct 6, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for bestwebsoft profile extra fields by bestwebsoft

Be the first to know when new medium vulnerabilities affecting bestwebsoft profile extra fields by bestwebsoft are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

bestwebsoft / Profile Extra Fields by BestWebSoft
0 โ‰ค 1.2.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/916c73e8-a150-4b35-8773-ea0ec29f7fd1?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/2975179/profile-extra-fields

Credits

Alex Thomas