PT-2022-17611 · WordPress · Advanced Custom Fields Pro

James Golovich

·

Published

2022-08-22

·

Updated

2022-08-23

·

CVE-2022-2594

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Custom Fields WordPress plugin versions prior to 5.12.3 Advanced Custom Fields Pro WordPress plugin versions prior to 5.12.3
Description The issue allows unauthenticated users to upload files, limited to those allowed in a default WordPress configuration, if a frontend form is available. This was introduced in the 5.0 rewrite and did not exist prior to that release.
Recommendations For Advanced Custom Fields WordPress plugin versions prior to 5.12.3, update to version 5.12.3 or later. For Advanced Custom Fields Pro WordPress plugin versions prior to 5.12.3, update to version 5.12.3 or later. As a temporary workaround, consider restricting access to frontend forms until the update is applied.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2594

Affected Products

Advanced Custom Fields Pro