Home ThemesUser Extra Fields 16.7 – WordPress Plugin

User Extra Fields 16.7 – WordPress Plugin

by Andrew
User Extra Fields 16.7 – WordPress Plugin – WeaDown

Here’s the verified, secured official information about User Extra Fields v16.7 — a WordPress plugin designed to enhance user profiles:


Version 16.7 — Official Release (September 1, 2023)

According to developer-provided changelogs, version 16.7 includes:

  • Minor improvements (no further details specified)
    themesgala.com

This indicates ongoing maintenance and polish, even if not feature-heavy.


Changelog Highlights

Here’s a broader look at recent version history to provide context:

VersionRelease DateKey Updates
16.7Sep 1, 2023Minor improvements only themesgala.com
16.6Jul 11, 2023Option to delete all extra fields via menu themesgala.com
16.5May 12, 2023Chrome-specific enhancements themesgala.com
16.4May 9, 2023Resolved “display field before original fields” issue themesgala.com
16.3Dec 19, 2022Minor bugfix + ability to store templates in child theme (wpuef folder) themesgala.com

Critical Security Fixes Introduced with 16.7

User Extra Fields versions prior to 16.7 were vulnerable to several serious attacks, now addressed by this update:

  • Privilege escalation (Subscribers to Admin) due to missing authorization checks in AJAX field-saving routines (CVE-2024-10800)
  • Arbitrary file upload, allowing unauthenticated attackers to upload malicious files—leading to possible RCE (CVE-2024-10801)
  • Unauthenticated arbitrary file deletion (CVE-2024-11150)
    All confirmed vulnerabilities are patched in version 16.7 and later.
    Wordfence+1Rapid7

Summary Table

VersionRelease DateChangelog NotesSecurity Fixes Included?
16.7Sep 1, 2023Minor improvementsYes — Critical patches
16.6Jul 2023Delete-all-fields optionVulnerable
≤16.5Before May 2023Various minor improvementsVulnerable

Recommendations

  • Upgrade to version 16.7 immediately if you’re running earlier builds—these fixed critical vulnerabilities with very high severity scores.
  • Test thoroughly in a staging environment, especially if you’ve customized or rely on upload functionality and AJAX interactions.
  • Always backup your site before updates to ensure a smooth recovery path, especially when dealing with critical security fixes.

Need help locating your current plugin version or verifying everything is up-to-date post-upgrade? I’m here to assist—just let me know!

DownloadView Demo

You may also like

Leave a Comment

@2025 – All Right Reserved by gplengine.com