First published: Mon Dec 13 2021(Updated: )
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | <5.11 | |
Advanced Custom Fields | <5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20867 is a vulnerability found in Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11.
The severity of CVE-2021-20867 is medium with a CVSS score of 6.5.
CVE-2021-20867 affects Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11.
The CWE of CVE-2021-20867 is CWE-862.
To fix CVE-2021-20867, upgrade to Advanced Custom Fields version 5.11 or higher.