CVE · High

CVE-2021-20866 — Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-20865, CVE-2021-20866, CVE-2021-20867 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11 Missing Authorization High 7.5 < 5.11 5.11 2021-12-02

CVE-2021-20865, CVE-2021-20866, CVE-2021-20867

Advanced Custom Fields versions prior to 5.11 contain multiple authorization flaws that allow unauthenticated or insufficiently privileged users to perform restricted actions. These vulnerabilities enable attackers to browse the database, retrieve user lists, and move field groups without proper permission checks. The plugin developer Delicious Brains addressed these authorization bypass issues in version 5.11.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.