Vulnerability Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advancedcustomfields | Advanced Custom Fields | >= 3.1.1, <= 6.0.2 |
Related Weaknesses (CWE)
References
- https://patchstack.com/database/vulnerability/advanced-custom-fields/wordpress-aThird Party Advisory
- https://patchstack.com/database/vulnerability/advanced-custom-fields/wordpress-aThird Party Advisory
FAQ
What is CVE-2022-40696?
CVE-2022-40696 is a vulnerability with a CVSS score of 3.7 (LOW). Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.
How severe is CVE-2022-40696?
CVE-2022-40696 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40696?
Check the references section above for vendor advisories and patch information. Affected products include: Advancedcustomfields Advanced Custom Fields.