Record summary

CVE-2023-7286 has a selected CVSS score of 6.5 (medium).

Description

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 15, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

ACF Quick Edit Fields Plugin for WordPress

Browse Jorn Lund / ACF Quick Edit Fields Plugin for WordPress
VulnCheckVersion data not supplied

Default status: unaffected

CVE ListThrough 3.2.2affected

References

4