CVE-2021-20866: Medium severity advanced custom fields vulnerability
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20866?
CVE-2021-20866 is a vulnerability found in Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11.
What is the severity of CVE-2021-20866?
The severity of CVE-2021-20866 is rated as medium with a CVSS score of 6.5.
What is the affected software for CVE-2021-20866?
The affected software for CVE-2021-20866 is Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11.
How can the CVE-2021-20866 vulnerability be exploited?
The CVE-2021-20866 vulnerability can be exploited by obtaining the user list and unauthorized information via unspecified vectors.
Are there any references available for CVE-2021-20866?
Yes, here are some references for CVE-2021-20866: [1] https://jvn.jp/en/jp/JVN09136401/index.html, [2] https://wordpress.org/plugins/advanced-custom-fields/, [3] https://www.advancedcustomfields.com/