The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above. | |
Title | ACF Quick Edit Fields <= 3.2.2 - Authenticated (Contributor+) Insecure Direct Object Reference | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T06:43:32.686Z
Updated: 2024-10-16T18:05:43.218Z
Reserved: 2024-10-15T18:04:41.302Z
Link: CVE-2023-7286
Vulnrichment
Updated: 2024-10-16T15:31:14.239Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T07:15:13.223
Modified: 2024-10-16T16:38:14.557
Link: CVE-2023-7286
Redhat
No data.