First published: Thu Aug 22 2019(Updated: )
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | <5.7.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the advanced-custom-fields plugin is CVE-2018-20986.
CVE-2018-20986 has a severity rating of medium (5.4).
CVE-2018-20986 affects the advanced-custom-fields plugin for WordPress by allowing authors to perform cross-site scripting (XSS) attacks through the plugin.
To fix CVE-2018-20986, you should update the advanced-custom-fields plugin to version 5.7.8 or higher.
You can find more information about CVE-2018-20986 on the WordPress plugin page and the Advanced Custom Fields website.