← back
CVE-2024-4565

Advanced Custom Fields < 6.3 - Contributor+ Custom Field Access

CVSS 7.5 HIGHEPSS 0.4%
The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →