Description
WordPress Plugin ACF to REST API is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin ACF to REST API version 3.2.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.0 or latest
References
https://gist.github.com/mariuszpoplwski/4fbaab7f271bea99c733e3f2a4bafbb5
https://github.com/airesvsg/acf-to-rest-api/issues/317
https://plugins.svn.wordpress.org/acf-to-rest-api/trunk/readme.txt
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2012-0788)
WebLogic CVE-2020-14645 Vulnerability (CVE-2020-14645)
Magento Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-7932)
WordPress Plugin All Category SEO Updater Cross-Site Scripting (0.2.7)
MySQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1626)