First published: Mon Dec 13 2021(Updated: )
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | <5.11 | |
Advanced Custom Fields | <5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20866 is a vulnerability found in Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11.
The severity of CVE-2021-20866 is rated as medium with a CVSS score of 6.5.
The affected software for CVE-2021-20866 is Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11.
The CVE-2021-20866 vulnerability can be exploited by obtaining the user list and unauthorized information via unspecified vectors.
Yes, here are some references for CVE-2021-20866: [1] https://jvn.jp/en/jp/JVN09136401/index.html, [2] https://wordpress.org/plugins/advanced-custom-fields/, [3] https://www.advancedcustomfields.com/