QID 730809
Date Published: 2023-05-23
QID 730809: WordPress Plugin Advanced Custom Fields Unauthenticated File Upload Vulnerability
Advanced Custom Fields (ACF) turns WordPress sites into a fully-fledged content management system by giving you all the tools to do more with your data.
CVE-2022-2594: Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration.
Affected Versions:
Advanced Custom Fields WordPress plugin versions from 5.0 prior to 5.12.3
QID Detection Logic(Unauthenticated):
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Advanced Custom Fields WordPress plugin.
Successful exploitation of this vulnerability may allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available.
- Advanced Custom Fields Plugin Release Notes -
wordpress.org/plugins/advanced-custom-fields/#developers
CVEs related to QID 730809
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Advanced Custom Fields Plugin Release Notes |
|