Extra User Details
Extra User Details has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for Extra User Details has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by LEE SE HYOUNG. Extra User Details is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2023-35878Extra User Details <= 0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Extra User Details
Author
Vadym
Extra User Details is the simple plugin that allows you to add extra fields to the user profile page (e.g. Facebook, Twitter, LinkedIn links etc). Extra fields can be easily accessed in your templates like a general wordpress author details: <?php the_author_meta('meta_key'); ?> Plugin saves fields data in wp_usermeta table. You can add and edit extra fields at plugin options section in backend.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C