CVE-2023-40068: XSS
Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40068?
The severity of CVE-2023-40068 is medium with a CVSS score of 5.4.
How does CVE-2023-40068 impact Advanced Custom Fields and Advanced Custom Fields Pro?
CVE-2023-40068 allows a remote authenticated attacker to execute arbitrary scripts on the web browser of users logging in to Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 with administrative privileges.
Which versions of Advanced Custom Fields and Advanced Custom Fields Pro are affected by CVE-2023-40068?
CVE-2023-40068 affects Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7.
How can I fix CVE-2023-40068?
To fix CVE-2023-40068, it is recommended to update to a version of Advanced Custom Fields or Advanced Custom Fields Pro that is higher than 6.1.7.
What is the CWE ID for CVE-2023-40068?
The CWE ID for CVE-2023-40068 is 79, which corresponds to the Cross-Site Scripting (XSS) vulnerability.