cleantalk
Vulnerabilities and Security Researches

Advanced Custom Fields (ACF), CVE-2023-1196

CVE, Research URL

CVE-2023-1196

Published on
May 02, 2023
Research Description
The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present.
Affected versions
Min -, max 6.1.8.
Status
vulnerable