Input validation vulnerability in Advanced Custom Fields (ACF) 6.3.6

A security vulnerability has been identified in the Advanced Custom Fields plugin for WordPress versions up to 6.3.7, which may allow unauthorized access and manipulation of custom post types by authenticated attackers with administrator-level access. This could potentially lead to unauthorized actions being performed by other users, but it is not a significant risk for most website owners. To fix this issue and ensure future updates, please follow the instructions in the provided reference.

Detected in:

Advanced Custom Fields (ACF) fixed vulnerable versions: >= * <= 6.3.6
Advanced Custom Fields (ACF®) fixed vulnerable versions:
Advanced Custom Fields Pro fixed vulnerable versions: >= * <= 6.3.8
Secure Custom Fields fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.