WordPress Plugin Vulnerabilities

ACF Quick Edit Fields < 3.2.3 - Contributor+ User Metadata Leak via IDOR

Description

The plugin does not restrict what user metadata created by the Advanced-Custom-Fields plugin should be accessible by a given user, enabling those without the `edit_users` capability to leak other users' custom metadata.

Proof of Concept

Affects Plugins

Fixed in 3.2.3

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Submitter
Chris Grello
Verified
Yes

Timeline

Publicly Published
2022-12-05 (about 3 years ago)
Added
2023-03-30 (about 2 years ago)
Last Updated
2023-03-30 (about 2 years ago)

Other