Vulnerabilities > Advancedcustomfields

DATE CVE VULNERABILITY TITLE RISK
2021-01-06 CVE-2020-36172 Cross-site Scripting vulnerability in Advancedcustomfields Advanced Custom Fields
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
4.3
2019-10-10 CVE-2015-9479 Unrestricted Upload of File with Dangerous Type vulnerability in Advancedcustomfields ACF Fronted Display
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
network
low complexity
advancedcustomfields CWE-434
7.5
2019-08-22 CVE-2018-20986 Cross-site Scripting vulnerability in Advancedcustomfields Advanced Custom Fields
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
3.5