NA

CVE-2023-30777

Published: 10/05/2023 Updated: 17/05/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

advancedcustomfields advanced custom fields

Github Repositories

Proof of Concept (PoC) URL generator for a reflected XSS vulnerability in the Advanced Custom Fields WordPress plugin.

CVE-2023-30777 Proof of Concept (PoC) URL generator for a reflected XSS vulnerability in the Advanced Custom Fields WordPress plugin PoC Generate by : Alucard0x1 Credit of Exploit : patchstackcom/articles/reflected-xss-in-advanced-custom-fields-plugins-affecting-2-million-sites/

Recent Articles

WordPress plugin hole puts '2 million websites' at risk
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources XSS marks the spot

WordPress users with the Advanced Custom Fields plugin on their website should upgrade after the discovery of a vulnerability in the code that could open up sites and their visitors to cross-site scripting (XSS) attacks. A warning from Patchstack about the flaw claimed there are more than two million active installs of the Advanced Custom Fields and Advanced Custom Fields Pro versions of the plugins, which are used to give site operators greater control of their content and data, such as edit sc...