What the vulnerability does
01Description
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
Explanation of Vulnerability in Simple Terms
The Advanced Custom Fields: Font Awesome Field plugin for WordPress does not properly check user permissions before allowing access to certain functionality. A logged-in user with low privileges can read data they should not have access to. The vulnerability affects versions up to 6.1.1. Site administrators should update to a version newer than 6.1.1 when available.
What an attacker can do
Read sensitive data they should not have access to based on their user role.
Potential impact on your site
Unauthorized users can access private or restricted information stored via the Font Awesome Field plugin.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities