Description
WordPress Plugin Advanced Custom Fields (ACF) is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently view arbitrary ACF data, move fields, or view field groups. WordPress Plugin Advanced Custom Fields (ACF) version 5.9.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.10 or latest
References
Related Vulnerabilities
MySQL NULL Pointer Dereference Vulnerability (CVE-2021-22570)
WordPress Plugin Flo Forms-Easy Drag & Drop Form Builder Multiple Vulnerabilities (1.0.35)
Internet Information Services Other Vulnerability (CVE-2003-0224)
Apache HTTP Server Resource Management Errors Vulnerability (CVE-2012-4557)
WordPress Plugin Merge+Minify+Refresh Cross-Site Request Forgery (1.10.6)