
Display custom fields in the frontend – Post and User Profile Fields Security & Risk Analysis
wordpress.org/plugins/shortcode-to-display-post-and-user-dataDisplay post and user custom fields data anywhere on the frontend using a shortcode, including advanced custom fields (ACF) fields.
Is Display custom fields in the frontend – Post and User Profile Fields Safe to Use in 2026?
Mostly Safe
Score 83/100Display custom fields in the frontend – Post and User Profile Fields is generally safe to use though it hasn't been updated recently. 4 past CVEs were resolved. Keep it updated.
The plugin "shortcode-to-display-post-and-user-data" version 1.3.0 exhibits a mixed security posture. On the positive side, static analysis shows no dangerous functions, all SQL queries use prepared statements, and output escaping is robust with 88% properly handled. The attack surface is limited to a single shortcode, with no unprotected entry points identified. Taint analysis also shows no critical or high-severity vulnerabilities, indicating a lack of immediately exploitable code injection or path traversal flaws in the analyzed flows.
However, significant concerns arise from the plugin's vulnerability history. Four known CVEs have been recorded, with a prevalence of medium-severity issues and a history including authorization bypass, cross-site scripting, code injection, and missing authorization. While there are currently no unpatched CVEs, this pattern suggests a history of recurring security weaknesses. The absence of nonce checks, despite the presence of capability checks, is another point of concern, as it could potentially be leveraged in conjunction with other vulnerabilities or in specific attack scenarios, particularly if the shortcode's functionality is complex or handles sensitive data without proper session validation.
Key Concerns
- History of 4 known CVEs
- Common vulnerability types found in history
- No nonce checks on entry points
- 88% output escaping, not 100%
Display custom fields in the frontend – Post and User Profile Fields Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Meta Disclosure
Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via vg_display_data
Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Code Injection
Display custom fields in the frontend – Post and User Profile Fields <= 1.2.0 - Missing Authorization via vg_display_data shortcode
Display custom fields in the frontend – Post and User Profile Fields Code Analysis
Output Escaping
Display custom fields in the frontend – Post and User Profile Fields Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Display custom fields in the frontend – Post and User Profile Fields Maintenance & Trust
Maintenance Signals
Community Trust
Display custom fields in the frontend – Post and User Profile Fields Alternatives
WP Page Templates
custom-page-templates-by-vegacorp
Create full width pages, add left or right sidebars, add above or below content sidebars.
Hide Header on Posts for Landing Pages
hide-header-on-posts-for-a-landing-page
Hide header on single post pages.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
Display custom fields in the frontend – Post and User Profile Fields Developer Profile
20 plugins · 30K total installs
How We Detect Display custom fields in the frontend – Post and User Profile Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
shortcode-to-display-post-and-user-data/style.css?ver=shortcode-to-display-post-and-user-data/script.js?ver=HTML / DOM Fingerprints
{{var}}