CVE-2022-23183
- EPSS 0.63%
- Veröffentlicht 31.03.2022 08:15:08
- Zuletzt bearbeitet 21.11.2024 06:48:08
Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permissio...
CVE-2021-20867
- EPSS 0.18%
- Veröffentlicht 13.12.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 05:47:18
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified ve...
CVE-2021-20866
- EPSS 0.39%
- Veröffentlicht 13.12.2021 07:15:06
- Zuletzt bearbeitet 21.11.2024 05:47:18
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified...
CVE-2021-20865
- EPSS 0.55%
- Veröffentlicht 13.12.2021 07:15:06
- Zuletzt bearbeitet 21.11.2024 05:47:18
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.
CVE-2021-24241
- EPSS 0.63%
- Veröffentlicht 22.04.2021 21:15:09
- Zuletzt bearbeitet 21.11.2024 05:52:40
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings page.
CVE-2020-36172
- EPSS 0.19%
- Veröffentlicht 06.01.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:28:53
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
CVE-2018-20986
- EPSS 0.23%
- Veröffentlicht 22.08.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:02:37
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.