Medium severity5.3NVD Advisory· Published Feb 5, 2024· Updated Apr 8, 2026
CVE-2024-1121
CVE-2024-1121
Description
The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_json_file() function in all versions up to, and including, 1.9.3.2. This makes it possible for unauthenticated attackers to export form settings.
Affected products
1- cpe:2.3:a:hookturn:advanced_forms_for_acf:*:*:*:*:*:wordpress:*:*Range: <=1.9.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/7b33f2ee-3f20-4494-bdae-3f8cc3c6dc73nvdThird Party Advisory
News mentions
0No linked articles in our index yet.