Record summary

CVE-2023-40068 has a selected CVSS score of 5.4 (medium).

Description

Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 4, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE Listversions 6.1.0 to 6.1.7affected
CVE Listversions 6.1.0 to 6.1.7affected

References

5