Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Acf To Rest Api Project Subscribe
Filtered by product Acf To Rest Api
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13700 1 Acf To Rest Api Project 1 Acf To Rest Api 2021-07-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.