Vulnerabilities (CVE)

Filtered by vendor Advancedcustomfields Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40068 1 Advancedcustomfields 1 Advanced Custom Fields 2023-08-25 N/A 5.4 MEDIUM
Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
CVE-2021-20867 1 Advancedcustomfields 1 Advanced Custom Fields 2021-12-15 4.0 MEDIUM 6.5 MEDIUM
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.
CVE-2021-20866 1 Advancedcustomfields 1 Advanced Custom Fields 2021-12-15 4.0 MEDIUM 6.5 MEDIUM
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.
CVE-2021-24241 1 Advancedcustomfields 1 Advanced Custom Fields 2021-04-29 4.3 MEDIUM 6.1 MEDIUM
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings page.
CVE-2020-36172 1 Advancedcustomfields 1 Advanced Custom Fields 2021-01-08 4.3 MEDIUM 6.1 MEDIUM
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
CVE-2018-20986 1 Advancedcustomfields 1 Advanced Custom Fields 2019-08-27 3.5 LOW 5.4 MEDIUM
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.