PT-2026-20577 · WordPress · Acf Photo Gallery Field

Rafshanzani Suhada

·

Publicado

2026-02-19

·

Atualizado

2026-02-23

·

CVE-2025-12081

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ACF Photo Gallery Field versions prior to 3.1
Description The ACF Photo Gallery Field plugin for WordPress has a flaw that allows unauthorized modification of data. This is due to a missing capability check within the acf photo gallery edit save function. Authenticated attackers with subscriber-level access or higher can modify the title, caption, and custom metadata of media attachments.
Recommendations Update ACF Photo Gallery Field to version 3.1 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12081

Produtos afetados

Acf Photo Gallery Field