Input validation vulnerability in Advanced Custom Fields (ACF) 3.5.1

Advanced Custom Fields up to version 3.5.1 is vulnerable to a type of security breach called Remote Code Execution. This means that malicious code can be stored on your website, giving attackers access to your data and allowing them to use your website for malicious purposes. This security breach can occur if the “allow_url_include” setting in the PHP programming language is turned on. By default, this setting is turned off.

Detected in:

Advanced Custom Fields (ACF) fixed vulnerable versions: >= * <= 3.5.1
Advanced Custom Fields (ACF®) fixed vulnerable versions:
Secure Custom Fields fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.