Record summary

CVE-2020-13700 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryThrough 3.1.0affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress acf-to-rest-api <=3.1.0 - Insecure Direct Object ReferenceCVSS 7.5

WordPress acf-to-rest-ap through 3.1.0 allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that can read sensitive information in the wp_options table such as the login and pass values.

Impact

An attacker can exploit this vulnerability to access sensitive data, such as user information or administrative credentials.

Remediation

Update the acf-to-rest-api plugin to version >3.1.0 or apply the latest security patches.

WeaknessesCWE-639
Authorspikpikcu
Template tagscvecve2020wordpresspluginacf_to_rest_api_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:acf_to_rest_api_project:acf_to_rest_api:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4