CVE-2020-13700
packagist/airesvsg/acf-to-rest-api
Information Exposure
An issue was discovered in the acf-to-rest-api plugin for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/
request that reads sensitive information in the wp_options
table, such as the login and password values.
All versions up to 3.1.0
Upgrade to version 3.2.0 or above.
2020-07-02
source |