CVE-2022-2594: Advanced Custom Fields 5.0-5.12.2 - Unauthenticated File Upload
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2594?
CVE-2022-2594 is a vulnerability in the Advanced Custom Fields WordPress plugin before version 5.12.3, and Advanced Custom Fields Pro WordPress plugin before version 5.12.3.
How severe is CVE-2022-2594?
CVE-2022-2594 has a severity rating of 8.8 out of 10, which is considered high.
What is the impact of CVE-2022-2594?
CVE-2022-2594 allows unauthenticated users to upload files allowed in a default WP configuration if there is a frontend form available.
Which versions are affected by CVE-2022-2594?
CVE-2022-2594 affects Advanced Custom Fields and Advanced Custom Fields Pro versions between 5.0.0 and 5.12.3.
How can I fix CVE-2022-2594?
To fix CVE-2022-2594, update your Advanced Custom Fields and Advanced Custom Fields Pro plugins to version 5.12.3 or newer.