Description
WordPress Plugin Advanced Forms for ACF Pro is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. WordPress Plugin Advanced Forms for ACF Pro version 1.6.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6.9 or latest
References
https://wpscan.com/vulnerability/364b0843-a990-4204-848a-60c928cc5bc0
https://plugins.svn.wordpress.org/advanced-forms/trunk/readme.txt
Related Vulnerabilities
SharePoint CVE-2020-1338 Vulnerability (CVE-2020-1338)
WordPress Plugin Ship To eCourier Cross-Site Request Forgery (1.0.1)
Java Unspesificed Vulnerability (CVE-2018-3150)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-15695)
Dolibarr Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-1010054)