Description
Insertion of Sensitive Information Into Sent Data vulnerability in airesvsg ACF to REST API acf-to-rest-api allows Retrieve Embedded Sensitive Data.This issue affects ACF to REST API: from n/a through <= 3.3.4.
Published: 2025-10-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ACF to REST API plugin for WordPress allows sensitive information stored in Advanced Custom Fields to be included and returned in REST API responses, exposing data to unauthorized receivers. This flaw, categorized as CWE‑201 (Sensitive Information Exposure), enables an attacker to retrieve embedded sensitive data from plugin endpoints, potentially exposing confidential configuration values, user data, or other private information. The plugin’s handling of data streams does not sanitize or restrict the content sent to clients, creating a direct leakage path.

Affected Systems

WordPress sites running the airesvsg ACF to REST API plugin version 3.3.4 or earlier. The vulnerability affects all releases from the initial deployment of the plugin up to and including 3.3.4.

Risk and Exploitability

The CVSS score of 5.3 places the vulnerability in a moderate severity range, yet the EPSS score of less than 1% indicates a very low probability of exploitation at this time. The issue is not listed in the CISA KEV catalog. The attack would likely originate from the REST API endpoint authenticated or unauthenticated, where an adversary could craft requests to trigger the exposure of sensitive data. While the impact is limited to data disclosure rather than code execution, the sensitivity of the leaked information could lead to significant compromise of site integrity or privacy. The overall risk remains moderate due to the nature of the data exposed, with low immediate exploitation likelihood but a persistent threat if the plugin remains unpatched.

Generated by OpenCVE AI on April 29, 2026 at 12:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ACF to REST API plugin to version 3.3.5 or later, which removes the vulnerability
  • If a patch is unavailable, disable the ACF to REST API plugin or restrict its REST API endpoints to authenticated users only
  • Review and audit any REST API endpoints that may still expose custom field data, ensuring that sensitive values are omitted or adequately protected

Generated by OpenCVE AI on April 29, 2026 at 12:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Mon, 27 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 02:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in airesvsg ACF to REST API acf-to-rest-api allows Retrieve Embedded Sensitive Data.This issue affects ACF to REST API: from n/a through <= 3.3.4.
Title WordPress ACF to REST API plugin <= 3.3.4 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:59:41.155Z

Reserved: 2025-10-24T14:25:07.970Z

Link: CVE-2025-62979

cve-icon Vulnrichment

Updated: 2025-10-27T13:54:55.905Z

cve-icon NVD

Status : Deferred

Published: 2025-10-27T02:15:58.677

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-62979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:45:11Z

Weaknesses