Impact
The ACF Flexible Layouts Manager plugin for WordPress contains a missing capability check that allows attackers who are not logged in to modify custom field values on individual posts and pages. This flaw permits unauthorized data alteration, directly compromising the integrity of website content.
Affected Systems
WordPress sites using the ACF Flexible Layouts Manager plugin version 1.1.6 or earlier are affected, regardless of theme or other plugins. Any instance of the plugin that has not been updated to a later release is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates the vulnerability is medium severity. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated remote user accessing the AJAX endpoint that triggers the missing authorization check, enabling the attacker to send crafted requests that alter post or page data.
OpenCVE Enrichment