The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. This makes it possible for authenticated attackers with contributor access and above, to extract sensitive data including arbitrary post metadata.
                
            References
                    Configurations
                    History
                    29 Jan 2025, 17:53
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-922 | |
| References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3069937%40custom-field-template&new=3069937%40custom-field-template&sfp_email=&sfph_mail= - Patch | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/7fcd0410-9423-4349-8d1c-3551de38a7c7?source=cve - Third Party Advisory | |
| CPE | cpe:2.3:a:wpgogo:custom_field_template:*:*:*:*:*:wordpress:*:* | |
| First Time | Wpgogo custom Field Template Wpgogo | 
Information
                Published : 2024-06-11 03:15
Updated : 2025-01-29 17:53
NVD link : CVE-2023-6748
Mitre link : CVE-2023-6748
CVE.ORG link : CVE-2023-6748
JSON object : View
Products Affected
                wpgogo
- custom_field_template
CWE
                
                    
                        
                        CWE-922
                        
            Insecure Storage of Sensitive Information
