Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23476 | The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present. |
Thu, 30 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-01-30T14:21:42.963Z
Reserved: 2023-03-06T13:01:50.110Z
Link: CVE-2023-1196
Updated: 2024-08-02T05:40:59.784Z
Status : Modified
Published: 2023-05-02T09:15:09.280
Modified: 2025-01-30T15:15:12.527
Link: CVE-2023-1196
No data.
OpenCVE Enrichment
No data.
EUVD