Vulnerabilities > Advancedcustomfields
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-01-06 | CVE-2020-36172 | Cross-site Scripting vulnerability in Advancedcustomfields Advanced Custom Fields The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS. | 4.3 |
2019-10-10 | CVE-2015-9479 | Unrestricted Upload of File with Dangerous Type vulnerability in Advancedcustomfields ACF Fronted Display The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php. | 7.5 |
2019-08-22 | CVE-2018-20986 | Cross-site Scripting vulnerability in Advancedcustomfields Advanced Custom Fields The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors. | 3.5 |