First published: Wed Oct 16 2024(Updated: )
The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | <=3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7286 is considered to have a medium severity due to its potential for unauthorized access to user metadata.
CVE-2023-7286 is related to Insecure Direct Object Reference in the ACF Quick Edit Fields plugin for WordPress.
To fix CVE-2023-7286, update the ACF Quick Edit Fields plugin to version 3.2.3 or later.
CVE-2023-7286 affects ACF Quick Edit Fields versions up to and including 3.2.2.
CVE-2023-7286 can be exploited by attackers who do not have the edit_users capability, allowing them access to metadata of other users.