Extra User Details

Extra User Details has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.4 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.

Every one of the 2 issues recorded for Extra User Details has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by LEE SE HYOUNG. Extra User Details is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Extra User Details vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2023-35878

Extra User Details <= 0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Extra User Details banner
Latestv0.5.3

Extra User Details

Vadym

Author

Vadym

4.7(10)
94/100
Last Updated
2024-10-12 (2y ago)
Active Installs
1,000+
Downloads
63,245
Requires WP
3.3+
Requires PHP
0+
Tested up to
WP 6.6.7
Created
2009-12-01 (17y ago)

Extra User Details is the simple plugin that allows you to add extra fields to the user profile page (e.g. Facebook, Twitter, LinkedIn links etc). Extra fields can be easily accessed in your templates like a general wordpress author details: <?php the_author_meta('meta_key'); ?> Plugin saves fields data in wp_usermeta table. You can add and edit extra fields at plugin options section in backend.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C