A new vulnerability was discovered in the Advanced Custom Fields plugin for WordPress and the users are recommended to update version 6.1.6
The security flaw which was assigned the identifier CVE-2023-30777, relates to a case of reflected cross-site scripting (XSS) that could be abused to inject arbitrary executable scripts into otherwise benign websites.
The plugin, which is available both as a free and pro version, has more than two million active installations. The issue was discovered and reported to the maintainers on May 2, 2023.
This vulnerability allows any unauthenticated user from stealing sensitive information to privilege escalation on the WordPress site by tricking a privileged user to visit the crafted URL path.
Reflected XSS attacks usually occur when victims are tricked into clicking on a bogus link sent via email or another route, causing the malicious code to be sent to the vulnerable website, which reflects the attack back to the user’s browser.
The CVE-2023-30777 can be activated on a default installation or configuration of Advanced Custom Fields, even though it is only possible to do so from logged-in users who have access to the plugin.
The development comes as Craft CMS patched two medium-severity XSS flaws (CVE-2023-30177 and CVE-2023-31144) that could be exploited by a threat actor to serve malicious payloads.
It also follows the disclosure of another XSS flaw in the cPanel product (CVE-2023-29489, CVSS score: 6.1) that could be exploited without any authentication to run arbitrary JavaScript.














Comments