Description
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
Remediation
References
Related Vulnerabilities
WordPress Plugin Invite Anyone Multiple Vulnerabilities (1.3.15)
WeBid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3815)
WordPress Plugin Zoho CRM Lead Magnet Cross-Site Scripting (1.6.9.1)
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Cross-Site Scripting (1.16.10)