nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-7286 CVE-2023-7286
MEDIUM
ACF Quick Edit Fields <= 3.2.2 - Authenticated (Contributor+) Insecure Direct Object Reference
Record summary
CVE-2023-7286 has a selected CVSS score of 6.5 (medium).
Description
The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 15, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ACF Quick Edit Fields Plugin for WordPressBrowse Jorn Lund / ACF Quick Edit Fields Plugin for WordPress | VulnCheck | Version data not supplied | |
ACF Quick Edit FieldsBrowse podpirate / ACF Quick Edit FieldsDefault status: unaffected | CVE List | Through 3.2.2 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?new=2828750%40acf-quickedit-fields&old=2816195%40acf-quickedit-fields wpscan.com
https://wpscan.com/vulnerability/3538e80e-c2c5-4e7b-97c3-b7debad7a136 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/5954bdc0-09e9-4691-95ff-02f7304514c9?source=cve