Summary:
CVE-2023-30777 is a newly discovered vulnerability in the WordPress plugin Advanced Custom Fields (ACF) which could be exploited by an attacker to perform a reflected cross-site scripting (XSS) attack. An unauthenticated user could use this vulnerability to inject arbitrary executable scripts into otherwise benign websites, potentially stealing sensitive information or performing privilege escalation. What's concerning is that this vulnerability can be activated even on a default installation or configuration of ACF. In addition, logged-in users who have access to the plugin are also at risk. ACF is a widely used plugin, with over a million installations, and the vulnerability affects all versions of the plugin before version 6.1.6. WordPress site administrators are strongly recommended to update their ACF plugin to the latest version as soon as possible to avoid the risk of exploitation.[/subscribe_to_unlock_form]
Summary:
CVE-2023-30777 is a newly discovered vulnerability in the WordPress plugin Advanced Custom Fields (ACF) which could be exploited by an attacker to perform a reflected cross-site scripting (XSS) attack. An unauthenticated user could use this vulnerability to inject arbitrary executable scripts into otherwise benign websites, potentially stealing sensitive information or performing privilege escalation. What's concerning is that this vulnerability can be activated even on a default installation or configuration of ACF. In addition, logged-in users who have access to the plugin are also at risk. ACF is a widely used plugin, with over a million installations, and the vulnerability affects all versions of the plugin before version 6.1.6. WordPress site administrators are strongly recommended to update their ACF plugin to the latest version as soon as possible to avoid the risk of exploitation.[emaillocker id="1283"]
Recommendations:
We strongly recommend you update Advanced Customer Fields (ACF) plugin for WordPress to version 6.1.6
References:
The following reports contain further technical details:
https://thehackernews.com/2023/05/new-vulnerability-in-popular-wordpress.html
[/emaillocker]