Vulnerabilities > CVE-2021-24865 - Unspecified vulnerability in Acf-Extended Advanced Custom Fields:Extended

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
acf-extended

Summary

The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue

Vulnerable Configurations

Part Description Count
Application
Acf-Extended
24