CVE-2021-20867: Medium severity advanced custom fields vulnerability
Published Dec 13, 2021
·Updated
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.
Affected Software
2 affected components
Advancedcustomfields Advanced Custom Fields Wordpress<5.11
Advancedcustomfields Advanced Custom Fields Wordpress<5.11
Event History
Dec 13, 2021
CVE Published
via MITRE·06:40 AM
Data Sourced
via MITRE·06:40 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20867?
CVE-2021-20867 is a vulnerability found in Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11.
2
What is the severity of CVE-2021-20867?
The severity of CVE-2021-20867 is medium with a CVSS score of 6.5.
3
How does CVE-2021-20867 affect the software?
CVE-2021-20867 affects Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11.
4
What is the CWE of CVE-2021-20867?
The CWE of CVE-2021-20867 is CWE-862.
5
How can I fix CVE-2021-20867?
To fix CVE-2021-20867, upgrade to Advanced Custom Fields version 5.11 or higher.