Input validation vulnerability in Advanced Custom Fields Pro 6.1.7

The Advanced Custom Fields PRO plugin for WordPress is insecure in versions 6.1 through 6.1.7. This means that if someone with administrator-level permissions or higher attempts to add certain information to certain pages on a WordPress website, they may be able to inject malicious web scripts into those pages. This vulnerability only affects multi-site installations and installations where the unfiltered_html feature has been disabled.

Detected in:

Advanced Custom Fields Pro fixed vulnerable versions: >= 6.1 <= 6.1.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.