CVSS Summary
| Score | 4.9 Medium |
|---|---|
| Vector | Network |
| Complexity | Medium |
| Authentication | Single |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | None |
Last revised:
This plugin allows users (who have permission to edit posts) to inject JavaScript into pages within /wp-admin/. This means a user can exceed their privileges by creating a script that causes an admin’s browser to perform an action, such as creating a new admin user, deleting all posts, etc.
Current state: Fixed
| Score | 4.9 Medium |
|---|---|
| Vector | Network |
| Complexity | Medium |
| Authentication | Single |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | None |
Tested with ACF PRO v5. Not tested with v4.
Update to version 1.1.13 or later.