CVE-2022-40696: WordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data Exposure
Published Jan 8, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.
Affected Software
1 affected component
Advancedcustomfields Advanced Custom Fields Wordpress>=3.1.1<=6.0.2
Remediation
Information
Update to 6.0.3 or a higher version.
Event History
Jan 8, 2024
CVE Published
via MITRE·10:02 PM
Data Sourced
via MITRE·10:02 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40696?
The severity of CVE-2022-40696 is classified as a medium risk vulnerability.
2
How do I fix CVE-2022-40696?
To fix CVE-2022-40696, update the Advanced Custom Fields plugin to version 6.0.3 or later.
3
What software versions are affected by CVE-2022-40696?
CVE-2022-40696 affects Advanced Custom Fields plugin versions from 3.1.1 to 6.0.2.
4
What type of vulnerability is CVE-2022-40696?
CVE-2022-40696 is an exposure of sensitive information to an unauthorized actor vulnerability.
5
Who is impacted by CVE-2022-40696?
Users of the Advanced Custom Fields plugin on WordPress sites using affected versions are impacted by CVE-2022-40696.