Pricing
Case studies
Login
Start trial
Advanced Custom Fields PRO
N/A
Developer
N/A
Latest version
N/A
Installations
N/A
Last updated
WordPress Plugin
No VDP
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
17 fixed
5 Mitigation rules
Authenticated (Admin+) Stored Cross-Site Scripting vulnerability
<= 6.3.8
Oct 16, 2024
Administrator+ Limited Arbitrary Function Call vulnerability
<= 6.3.7
Oct 9, 2024
Missing Authorization to Information Disclosure vulnerability
< 5.11
Oct 4, 2024
Missing Authorization to Information Disclosure vulnerability
< 5.11
Oct 4, 2024
Missing Authorization on Option Changes vulnerability
< 5.11
Oct 4, 2024
Cross-Site Request Forgery (CSRF) vulnerability
< 6.3.2
Jun 26, 2024
Subscriber+ Broken Access Control vulnerability
< 6.3.2
Jun 26, 2024
Contributor+ Broken Access Control vulnerability
< 6.3.2
Jun 26, 2024
Auth. Custom Field Access vulnerability
< 6.3
Jun 3, 2024
Contributor+ Local File Inclusion vulnerability
< 6.2.10
May 15, 2024
Contributor+ Arbitrary Function Execution vulnerability
< 6.2.10
May 15, 2024
Contributor+ Stored Cross-Site Scripting vulnerability
< 6.2.5
Jan 16, 2024
Auth. Stored Cross-Site Scripting (XSS) vulnerability
6.1-6.1.7
Aug 10, 2023
Reflected Cross Site Scripting (XSS) vulnerability
<= 6.1.5
May 5, 2023
Contributor+ PHP Object Injection vulnerability
< 6.1.0
May 2, 2023
Unauthenticated File Upload vulnerability
<= 5.12.2
Aug 1, 2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 5.9.0
Apr 2, 2021