PT-2024-16827 · WordPress · Advanced Forms For Acf

Francesco Carlucci

·

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2024-1121

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advanced Forms for ACF plugin for WordPress versions prior to 1.9.3.3
Description The issue is related to unauthorized access of data due to a missing capability check on the export json file() function. This allows unauthenticated attackers to export form settings.
Recommendations For versions up to and including 1.9.3.2, update to a version newer than 1.9.3.2 to resolve the issue. As a temporary workaround, consider disabling the export json file() function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1121

Affected Products

Advanced Forms For Acf