First published: Mon Jan 08 2024(Updated: )
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | >=3.1.1<=6.0.2 |
Update to 6.0.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-40696 is classified as a medium risk vulnerability.
To fix CVE-2022-40696, update the Advanced Custom Fields plugin to version 6.0.3 or later.
CVE-2022-40696 affects Advanced Custom Fields plugin versions from 3.1.1 to 6.0.2.
CVE-2022-40696 is an exposure of sensitive information to an unauthorized actor vulnerability.
Users of the Advanced Custom Fields plugin on WordPress sites using affected versions are impacted by CVE-2022-40696.