WPEngine Advanced Custom Fields
cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:wordpress:*:*
- < 6.4.3
A vulnerability allowing HTML injection has been identified in the WordPress plugin Advanced Custom Fields, affecting versions prior to 6.4.3. This vulnerability allows crafted HTML to be rendered, potentially tampering with the page display.
Exploitation of this vulnerability could lead to unauthorized HTML being injected and rendered, allowing for manipulation of the page's appearance.
Users are advised to update the Advanced Custom Fields plugin to version 6.4.3 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.