The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-08-22T15:05:03
Updated: 2024-08-03T00:39:08.043Z
Reserved: 2022-08-01T00:00:00
Link: CVE-2022-2594
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-08-22T15:15:15.653
Modified: 2024-11-21T07:01:18.993
Link: CVE-2022-2594
Redhat
No data.