Beta

Report

Advanced Custom Fields PRO < 5.11 is vulnerable to Missing Authorization to Information Disclosure vulnerability

Contributor
Published
2024-10-03

Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.

CVSS

Score:4.3

Severity:Medium

Version:< 5.11

There is a patch available in v5.11 and we strongly recommend you update to this version as soon as possible.