CVE Database /
CVE-2022-40696
CVE · Low
CVE-2022-40696 — Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 3.1.1 - <= 6.0.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-40696
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 3.1.1 - <= 6.0.2 |
Exposure of Sensitive Information to an Unauthorized Actor |
Low
3.7
|
3.1.1–6.0.2
|
6.0.2 |
2022-10-18 |
—
|
CVE-2022-40696
The Advanced Custom Fields plugin through version 6.0.2 allows contributor-level users on some WordPress installations to access and retrieve sensitive information about users or site configuration through the ACF shortcode, despite the shortcode's normal validation of field data.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings