CVE-2021-20865: High severity advanced custom fields vulnerability
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20865?
CVE-2021-20865 is a vulnerability in Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 that allows unauthorized browsing of the database.
How severe is CVE-2021-20865?
CVE-2021-20865 has a severity level of 7.5 (high).
What is the affected software for CVE-2021-20865?
The affected software for CVE-2021-20865 is Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11.
How can I fix CVE-2021-20865?
To fix CVE-2021-20865, users should update to Advanced Custom Fields version 5.11 or higher.
Is there any additional information about CVE-2021-20865?
For more information about CVE-2021-20865, you can visit the following references: [link1](https://jvn.jp/en/jp/JVN09136401/index.html), [link2](https://wordpress.org/plugins/advanced-custom-fields/), [link3](https://www.advancedcustomfields.com/)