QID 995947
Date Published: 2023-11-16
QID 995947: PHP (Composer) Security Update for airesvsg/acf-to-rest-api (GHSA-r345-x8hr-2r9p)
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-r345-x8hr-2r9p for updates and patch information.
Vendor References
- GHSA-r345-x8hr-2r9p -
github.com/advisories/GHSA-r345-x8hr-2r9p
CVEs related to QID 995947
Software Advisories
| Advisory ID | Software | Component | Link |
|---|