Display custom fields in the frontend – Post and User Profile Fields Security & Risk Analysis

wordpress.org/plugins/shortcode-to-display-post-and-user-data

Display post and user custom fields data anywhere on the frontend using a shortcode, including advanced custom fields (ACF) fields.

600 active installs v1.3.0 PHP + WP 4.1+ Updated Jan 12, 2024
acfcustom-fieldscustom-pageswordpress-templateswp-page-templates
83
B · Generally Safe
CVEs total4
Unpatched0
Last CVEJan 16, 2024
Download
Safety Verdict

Is Display custom fields in the frontend – Post and User Profile Fields Safe to Use in 2026?

Mostly Safe

Score 83/100

Display custom fields in the frontend – Post and User Profile Fields is generally safe to use though it hasn't been updated recently. 4 past CVEs were resolved. Keep it updated.

4 known CVEsLast CVE: Jan 16, 2024Updated 2yr ago
Risk Assessment

The plugin "shortcode-to-display-post-and-user-data" version 1.3.0 exhibits a mixed security posture. On the positive side, static analysis shows no dangerous functions, all SQL queries use prepared statements, and output escaping is robust with 88% properly handled. The attack surface is limited to a single shortcode, with no unprotected entry points identified. Taint analysis also shows no critical or high-severity vulnerabilities, indicating a lack of immediately exploitable code injection or path traversal flaws in the analyzed flows.

However, significant concerns arise from the plugin's vulnerability history. Four known CVEs have been recorded, with a prevalence of medium-severity issues and a history including authorization bypass, cross-site scripting, code injection, and missing authorization. While there are currently no unpatched CVEs, this pattern suggests a history of recurring security weaknesses. The absence of nonce checks, despite the presence of capability checks, is another point of concern, as it could potentially be leveraged in conjunction with other vulnerabilities or in specific attack scenarios, particularly if the shortcode's functionality is complex or handles sensitive data without proper session validation.

Key Concerns

  • History of 4 known CVEs
  • Common vulnerability types found in history
  • No nonce checks on entry points
  • 88% output escaping, not 100%
Vulnerabilities
4

Display custom fields in the frontend – Post and User Profile Fields Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
3 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
3

4 total CVEs

CVE-2023-6983medium · 4.3Authorization Bypass Through User-Controlled Key

Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Meta Disclosure

Jan 16, 2024 Patched in 1.3.0 (196d)
CVE-2023-6982medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via vg_display_data

Jan 16, 2024 Patched in 1.3.0 (196d)
CVE-2023-6996high · 8.8Improper Control of Generation of Code ('Code Injection')

Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Code Injection

Jan 16, 2024 Patched in 1.3.0 (196d)
CVE-2023-31073medium · 6.5Missing Authorization

Display custom fields in the frontend – Post and User Profile Fields <= 1.2.0 - Missing Authorization via vg_display_data shortcode

Apr 24, 2023 Patched in 1.2.1 (274d)
Code Analysis
Analyzed Mar 16, 2026

Display custom fields in the frontend – Post and User Profile Fields Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
7 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped8 total outputs
Attack Surface

Display custom fields in the frontend – Post and User Profile Fields Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[vg_display_data] index.php:51
WordPress Hooks 2
actionadmin_initsettings.php:13
actionadmin_menusettings.php:14
Maintenance & Trust

Display custom fields in the frontend – Post and User Profile Fields Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 12, 2024
PHP min version
Downloads13K

Community Trust

Rating100/100
Number of ratings8
Active installs600
Developer Profile

Display custom fields in the frontend – Post and User Profile Fields Developer Profile

Jose Vega

20 plugins · 30K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
258 days
View full developer profile
Detection Fingerprints

How We Detect Display custom fields in the frontend – Post and User Profile Fields

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
shortcode-to-display-post-and-user-data/style.css?ver=shortcode-to-display-post-and-user-data/script.js?ver=

HTML / DOM Fingerprints

Shortcode Output
{{var}}
FAQ

Frequently Asked Questions about Display custom fields in the frontend – Post and User Profile Fields