Show filters
123 Total Results
Displaying 101-110 of 123
Sort by:
Attacker Value
Unknown
CVE-2021-20866
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-20865
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-24241
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings page.
0
Attacker Value
Unknown
CVE-2020-36172
Disclosure Date: January 06, 2021 (last updated February 22, 2025)
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
0
Attacker Value
Unknown
CVE-2020-7228
Disclosure Date: January 22, 2020 (last updated February 21, 2025)
The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.
0
Attacker Value
Unknown
CVE-2017-18609
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter.
0
Attacker Value
Unknown
CVE-2017-18611
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css parameter.
0
Attacker Value
Unknown
CVE-2017-18610
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id parameter.
0
Attacker Value
Unknown
CVE-2018-20986
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
0
Attacker Value
Unknown
CVE-2013-7476
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
0