CVE · Low

CVE-2022-40696 — Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 3.1.1 - <= 6.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-40696 Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 3.1.1 - <= 6.0.2 Exposure of Sensitive Information to an Unauthorized Actor Low 3.7 3.1.1–6.0.2 6.0.2 2022-10-18

CVE-2022-40696

The Advanced Custom Fields plugin through version 6.0.2 allows contributor-level users on some WordPress installations to access and retrieve sensitive information about users or site configuration through the ACF shortcode, despite the shortcode's normal validation of field data.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.