SB2021120202 - Multiple vulnerabilities in Advanced Custom Fields plugin for WordPress
Published: December 2, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Missing Authorization (CVE-ID: CVE-2021-20865)
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to missing authorization related to database browsing. A remote authenticated attacker can browse unauthorized data on the database
2) Missing Authorization (CVE-ID: CVE-2021-20866)
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to missing authorization related to user list obtaining. A remote authenticated attacker can obtain a list of information that an user do not have the privilege for.
3) Missing Authorization (CVE-ID: CVE-2021-20867)
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to missing authorization related to field group movement. A remote authenticated attacker can move field groups that an user do not have permission to use.
Remediation
Install update from vendor's website.