CVSS Summary
| Score | 4.9 Medium | 
|---|---|
| Vector | Network | 
| Complexity | Medium | 
| Authentication | Single | 
| Confidentiality | Partial | 
| Integrity | Partial | 
| Availability | None | 
Last revised:
This plugin allows users (who have permission to edit posts) to inject JavaScript into pages within /wp-admin/. This means a user can exceed their privileges by creating a script that causes an admin’s browser to perform an action, such as creating a new admin user, deleting all posts, etc.
Current state: Fixed
| Score | 4.9 Medium | 
|---|---|
| Vector | Network | 
| Complexity | Medium | 
| Authentication | Single | 
| Confidentiality | Partial | 
| Integrity | Partial | 
| Availability | None | 
Tested with ACF PRO v5. Not tested with v4.
Update to version 1.1.13 or later.