Show filters
123 Total Results
Displaying 101-110 of 123
Sort by:
Attacker Value
Unknown

CVE-2021-20866

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.
Attacker Value
Unknown

CVE-2021-20865

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.
Attacker Value
Unknown

CVE-2021-24241

Disclosure Date: April 22, 2021 (last updated February 22, 2025)
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings page.
Attacker Value
Unknown

CVE-2020-36172

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
Attacker Value
Unknown

CVE-2020-7228

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.
Attacker Value
Unknown

CVE-2017-18609

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter.
Attacker Value
Unknown

CVE-2017-18611

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css parameter.
Attacker Value
Unknown

CVE-2017-18610

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id parameter.
Attacker Value
Unknown

CVE-2018-20986

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
0
Attacker Value
Unknown

CVE-2013-7476

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
0