Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-59165 | The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the user_meta shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve potentially sensitive user meta. |
Wed, 08 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kylebjohnson:user_shortcodes_plus:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | User Shortcodes Plus <= 2.0.2 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via user_meta Shortcode | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 07 Feb 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kylebjohnson
Kylebjohnson user Shortcodes Plus |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:kylebjohnson:user_shortcodes_plus:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Kylebjohnson
Kylebjohnson user Shortcodes Plus |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:01:33.405Z
Reserved: 2023-12-19T21:53:12.729Z
Link: CVE-2023-6969
Updated: 2024-08-02T08:50:06.964Z
Status : Modified
Published: 2024-03-13T16:15:09.703
Modified: 2026-04-08T18:18:46.007
Link: CVE-2023-6969
No data.
OpenCVE Enrichment
No data.
EUVD