CVE-2023-7286

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above.
Configurations

No configuration.

History

16 Oct 2024, 16:38

Type Values Removed Values Added
Summary
  • (es) El complemento ACF Quick Edit Fields para WordPress es vulnerable a la referencia directa a objetos inseguros en versiones hasta la 3.2.2 incluida. Esto permite que los atacantes sin la capacidad edit_users accedan a los metadatos de otros usuarios, incluidos los usuarios de nivel colaborador y superiores.

16 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-16 07:15

Updated : 2024-10-16 16:38


NVD link : CVE-2023-7286

Mitre link : CVE-2023-7286

CVE.ORG link : CVE-2023-7286


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key