CVE-2021-20865, CVE-2021-20866, CVE-2021-20867
Advanced Custom Fields versions before 5.11 contain three separate authorization flaws that allow unauthorized actions: browsing the database without proper permission checks, retrieving user lists without authorization, and moving field groups without sufficient access controls. These vulnerabilities stem from missing authorization validation in the plugin's functionality. The issues were identified by Keitaro Yamazaki of Ierae Security, Inc and coordinated through JPCERT/CC with the plugin developer.
Based on public CVE data (MITRE/NVD).