Vulnerability Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advancedcustomfields | Advanced Custom Fields | < 6.1.6 |
Related Weaknesses (CWE)
References
- https://patchstack.com/articles/reflected-xss-in-advanced-custom-fields-plugins-ExploitThird Party Advisory
- https://patchstack.com/database/vulnerability/advanced-custom-fields-pro/wordpreThird Party Advisory
- https://patchstack.com/database/vulnerability/advanced-custom-fields/wordpress-aThird Party Advisory
- https://patchstack.com/articles/reflected-xss-in-advanced-custom-fields-plugins-ExploitThird Party Advisory
- https://patchstack.com/database/vulnerability/advanced-custom-fields-pro/wordpreThird Party Advisory
- https://patchstack.com/database/vulnerability/advanced-custom-fields/wordpress-aThird Party Advisory
FAQ
What is CVE-2023-30777?
CVE-2023-30777 is a vulnerability with a CVSS score of 7.1 (HIGH). Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.
How severe is CVE-2023-30777?
CVE-2023-30777 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30777?
Check the references section above for vendor advisories and patch information. Affected products include: Advancedcustomfields Advanced Custom Fields.