PT-2022-17611 · WordPress · Advanced Custom Fields Pro
James Golovich
·
Published
2022-08-22
·
Updated
2022-08-23
·
CVE-2022-2594
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advanced Custom Fields WordPress plugin versions prior to 5.12.3
Advanced Custom Fields Pro WordPress plugin versions prior to 5.12.3
Description
The issue allows unauthenticated users to upload files, limited to those allowed in a default WordPress configuration, if a frontend form is available. This was introduced in the 5.0 rewrite and did not exist prior to that release.
Recommendations
For Advanced Custom Fields WordPress plugin versions prior to 5.12.3, update to version 5.12.3 or later.
For Advanced Custom Fields Pro WordPress plugin versions prior to 5.12.3, update to version 5.12.3 or later.
As a temporary workaround, consider restricting access to frontend forms until the update is applied.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Custom Fields Pro