PT-2022-9503 · WordPress · Acf Photo Gallery Field

Krzysztof Zając

·

Published

2022-01-17

·

Updated

2023-08-02

·

CVE-2021-24909

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ACF Photo Gallery Field WordPress plugin versions prior to 1.7.5
Description The issue arises from the lack of sanitization and escaping of the post parameter in the includes/acf photo gallery metabox edit.php file, leading to a Reflected Cross-Site Scripting issue. This allows malicious code to be injected and executed, potentially compromising the security of the system.
Recommendations For versions prior to 1.7.5, update to version 1.7.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the includes/acf photo gallery metabox edit.php file until a patch is applied. Avoid using the post parameter in the affected file until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-24909

Affected Products

Acf Photo Gallery Field