Lucene search

K
cvelistPatchstackCVELIST:CVE-2023-30777
HistoryMay 10, 2023 - 5:50 a.m.

CVE-2023-30777 WordPress Advanced Custom Fields / Advanced Custom Fields PRO plugins <= 6.1.5 vulnerable to Cross Site Scripting (XSS)

2023-05-1005:50:04
CWE-79
Patchstack
www.cve.org
wordpress
advanced custom fields
pro
xss
vulnerability
wp engine

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

0.006 Low

EPSS

Percentile

78.4%

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <=Β 6.1.5 versions.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Advanced Custom Fields Pro",
    "vendor": "WP Engine",
    "versions": [
      {
        "changes": [
          {
            "at": "6.1.6",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.1.5",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  },
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "advanced-custom-fields",
    "product": "Advanced Custom Fields",
    "vendor": "WP Engine",
    "versions": [
      {
        "changes": [
          {
            "at": "6.1.6",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.1.5",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

0.006 Low

EPSS

Percentile

78.4%