User Specific Content
User Specific Content has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for User Specific Content has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Muhammad Yudha - DJ. User Specific Content is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.7.0.
CVE-2025-62749User Specific Content <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

User Specific Content
Author
Bainternet
This Plugin allows you to select specific users by user name, or by role name who can view a specific post content or page content. Basically it adds a meta box to the post or page edit screen and lets the user select specific users by name or roles and then when you call that page content using “the_content();” function it check using “the_content” filter if the current user is one of the users you have selected or if his role match’s the roles you have selected and shows the content, otherwise it displays a message Features: You can select any number of Users you want by there names. You can select any number of users Roles you want by there names. Easy Customization of content blocked massage per post, page or custom type. Works with both posts,pages and custom types. Content to none logged in users only. Setup global default blocked message. plugin blocks when using the_content filter and/or the_excerpt on admin selection. Simple admin Panel. Block Multiple contents on a single post/page for multiple users Using ShortCode. New admin panel. Change metabox settings (new) in option panel help tabs. Any feedback or suggestions are welcome. Also check out my other plugins
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C