High severity7.1NVD Advisory· Published May 10, 2023· Updated Jun 17, 2026
CVE-2023-30777
CVE-2023-30777
Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:-:wordpress:*:*+ 1 more
- cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:-:wordpress:*:*range: <6.1.6
- cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:pro:wordpress:*:*range: <6.1.6
- Range: <=6.1.5
- Range: <=6.1.5
- WP Engine/Advanced Custom Fieldsv5Range: n/a
- WP Engine/Advanced Custom Fields Prov5Range: n/a
Patches
Vulnerability mechanics
References
3- patchstack.com/articles/reflected-xss-in-advanced-custom-fields-plugins-affecting-2-million-sitesnvdExploitThird Party Advisory
- patchstack.com/database/vulnerability/advanced-custom-fields-pro/wordpress-advanced-custom-fields-pro-plugin-6-1-5-reflected-cross-site-scripting-xss-vulnerabilitynvdThird Party Advisory
- patchstack.com/database/vulnerability/advanced-custom-fields/wordpress-advanced-custom-fields-plugin-6-1-5-reflected-cross-site-scripting-xss-vulnerabilitynvdThird Party Advisory
News mentions
0No linked articles in our index yet.