Vulnerability Details CVE-2022-23183
Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permission.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.5%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2022-23183
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:-
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.10
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.10.1
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.10.2
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.11
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.11.1
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.11.2
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.11.3
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.11.4
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.12
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.8.13
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.8.14
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.0
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.1
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.2
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.3
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.4
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.5
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.6
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.7
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.8
-
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:5.9.9