CVE-2018-20986: XSS
Published Aug 22, 2019
·Updated
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
Affected Software
1 affected component
Advancedcustomfields Advanced Custom Fields Wordpress<5.7.8
Event History
Aug 22, 2019
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the advanced-custom-fields plugin?
The vulnerability ID for the advanced-custom-fields plugin is CVE-2018-20986.
2
What is the severity rating of CVE-2018-20986?
CVE-2018-20986 has a severity rating of medium (5.4).
3
How does CVE-2018-20986 affect the advanced-custom-fields plugin for WordPress?
CVE-2018-20986 affects the advanced-custom-fields plugin for WordPress by allowing authors to perform cross-site scripting (XSS) attacks through the plugin.
4
How can I fix CVE-2018-20986?
To fix CVE-2018-20986, you should update the advanced-custom-fields plugin to version 5.7.8 or higher.
5
Where can I find more information about CVE-2018-20986?
You can find more information about CVE-2018-20986 on the WordPress plugin page and the Advanced Custom Fields website.