CVE Database /
CVE-2022-23183
CVE · Medium
CVE-2022-23183 — Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-23183
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1 |
Missing Authorization |
Medium
6.5
|
< 5.12.1
|
5.12.1 |
2022-03-30 |
—
|
CVE-2022-23183
The Advanced Custom Fields plugin for WordPress prior to version 5.12.1 contains an authorization bypass vulnerability caused by insufficient capability validation. This flaw allows any authenticated user with editor-level permissions or higher, including contributors, to access sensitive database information they should not be permitted to view. The vulnerability stems from the plugin's failure to properly verify user permissions before exposing data.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings