Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permission.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.advancedcustomfields.com/ | product vendor advisory |
https://wordpress.org/plugins/advanced-custom-fields/ | product third party advisory |
https://jvn.jp/en/jp/JVN42543427/index.html | third party advisory |