Description
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
Remediation
References
Related Vulnerabilities
WordPress Plugin S3 Video Cross-Site Scripting (0.982)
MySQL CVE-2024-20965 Vulnerability (CVE-2024-20965)
PHP Improper Input Validation Vulnerability (CVE-2015-5589)
WordPress Plugin JetWidgets For Elementor Multiple Cross-Site Scripting Vulnerabilities (1.0.8)
Django Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2025-32873)