First published: Mon Aug 22 2022(Updated: )
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | >=5.0.0<5.12.3 | |
Advanced Custom Fields | >=5.0.0<5.12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2594 is a vulnerability in the Advanced Custom Fields WordPress plugin before version 5.12.3, and Advanced Custom Fields Pro WordPress plugin before version 5.12.3.
CVE-2022-2594 has a severity rating of 8.8 out of 10, which is considered high.
CVE-2022-2594 allows unauthenticated users to upload files allowed in a default WP configuration if there is a frontend form available.
CVE-2022-2594 affects Advanced Custom Fields and Advanced Custom Fields Pro versions between 5.0.0 and 5.12.3.
To fix CVE-2022-2594, update your Advanced Custom Fields and Advanced Custom Fields Pro plugins to version 5.12.3 or newer.