Medium severity6.1NVD Advisory· Published Jan 6, 2021· Updated Jun 17, 2026
CVE-2020-36172
CVE-2020-36172
Description
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:*:wordpress:*:*Range: <5.8.12
- WordPress/Advanced Custom Fields plugindescription
- Range: <5.8.12
Patches
Vulnerability mechanics
References
1- wordpress.org/plugins/advanced-custom-fields/nvdProductThird Party Advisory
News mentions
0No linked articles in our index yet.