Force First and Last Name as Display Name
Force First and Last Name as Display Name has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Force First and Last Name as Display Name has a vendor fix available, so running the current release closes it.
All of these findings were reported by Kévin Mosbahi (Mika). Force First and Last Name as Display Name is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2023-28419Force First and Last Name as Display Name <= 1.2 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Force First and Last Name as Display Name
Author
Andrew Lima
This plugin hides the “Display Name” field on the Edit Profile screen for all users. Instead of allowing users to set this field, the plugin will always set the User field display_name to their first and last name. If these field are empty, display_name will be set to their username. Display names are set when the user registers as well as when a user’s profile is updated via the WordPress admin. The plugin includes a batch process to update the display name for existing users. Navigate to Settings > Force First Last in the WordPress admin to run the update.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C