Medium severity6.5NVD Advisory· Published Mar 31, 2022· Updated Jun 17, 2026
CVE-2022-23183
CVE-2022-23183
Description
Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permission.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:-:wordpress:*:*+ 1 more
- cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:-:wordpress:*:*range: <5.12.1
- cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:pro:wordpress:*:*range: <5.12.1
- Range: <5.12.1
- Delicious Brains/Advanced Custom Fieldsv5Range: Advanced Custom Fields versions prior to 5.12.1, and Advanced Custom Fields Pro versions prior to 5.12.1
Patches
Vulnerability mechanics
References
3- jvn.jp/en/jp/JVN42543427/index.htmlnvdThird Party Advisory
- wordpress.org/plugins/advanced-custom-fields/nvdProductThird Party Advisory
- www.advancedcustomfields.comnvdProductVendor Advisory
News mentions
0No linked articles in our index yet.