What the vulnerability does
01Description
Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.
Explanation of Vulnerability in Simple Terms
02Summary
Advanced Custom Fields PRO versions up to 6.3.1 lack proper authorization checks on certain operations. A logged-in user with low privileges can read or modify data they should not have access to. The vulnerability requires an active user account but no special interaction. Update to a version newer than 6.3.1.
What an attacker can do
03Attacker Capabilities
Read or modify data belonging to other users or restricted fields without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can access or alter custom field data across your site, risking data exposure and integrity.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the WordPress site.
Key dates
06Disclosure timeline
November 1, 2024
CVE published
April 28, 2026
Record updated