Vulnerabilities > Advancedcustomfields > Advanced Custom Fields

DATE CVE VULNERABILITY TITLE RISK
2021-04-22 CVE-2021-24241 Cross-site Scripting vulnerability in Advancedcustomfields Advanced Custom Fields
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings page.
4.3
2021-01-06 CVE-2020-36172 Cross-site Scripting vulnerability in Advancedcustomfields Advanced Custom Fields
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
4.3
2019-08-22 CVE-2018-20986 Cross-site Scripting vulnerability in Advancedcustomfields Advanced Custom Fields
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
3.5