Description
WordPress Plugin Advanced Custom Fields PRO is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently view the information on the database. WordPress Plugin Advanced Custom Fields PRO version 5.12 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.12.1 or latest
References
Related Vulnerabilities
Moodle CVE-2024-34005 Vulnerability (CVE-2024-34005)
WordPress Plugin Code Insert Manager (Q2W3 Inc Manager) ZeroClipboard Cross-Site Scripting (2.3.1)
WordPress Plugin CMS Tree Page View Security Bypass (1.3.4)
MySQL CVE-2018-2591 Vulnerability (CVE-2018-2591)
WordPress Plugin LayerSlider Cross-Site Request Forgery (4.6.1)