First published: Wed May 10 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | <6.1.6 | |
Advanced Custom Fields | <6.1.6 |
Update to 6.1.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-30777.
The severity of CVE-2023-30777 is high with a CVSS score of 6.1.
The Advanced Custom Fields Pro and Advanced Custom Fields plugins versions up to 6.1.5 for WordPress are affected.
Update the WP Engine Advanced Custom Fields Pro and WP Engine Advanced Custom Fields plugins to version 6.1.6 or higher.
You can find more information about CVE-2023-30777 at the following references: [Link 1](https://patchstack.com/articles/reflected-xss-in-advanced-custom-fields-plugins-affecting-2-million-sites?_s_id=cve), [Link 2](https://patchstack.com/database/vulnerability/advanced-custom-fields-pro/wordpress-advanced-custom-fields-pro-plugin-6-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve), [Link 3](https://patchstack.com/database/vulnerability/advanced-custom-fields/wordpress-advanced-custom-fields-plugin-6-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve).