Advanced Custom Fields (ACF), CVE-2023-40068
- CVE, Research URL
- Home page URL
- Application
- Published on
- Aug 21, 2023
- Research Description
- Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
- Affected versions
-
Min 6.1.0, max 6.1.7.
- Status
-
vulnerable