Access violation vulnerability in Advanced Custom Fields (ACF) 5.12.2

The Advanced Custom Fields plugin for WordPress is vulnerable to file uploads in versions up to 5.12.2. This vulnerability allows people who don’t have permission to upload files (like contributors or visitors to the website) to upload certain types of files. Even though WordPress still checks the types of files and their extensions

Detected in:

Advanced Custom Fields (ACF) fixed vulnerable versions: >= * <= 5.12.2
Advanced Custom Fields (ACF®) fixed vulnerable versions:
Secure Custom Fields fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.