2 million sites are affected, WordPress plug-in ACF is exposed high-risk vulnerabilities
CTOnews.com May 10 news, Advanced Custom Fields (ACF) is a frequently used WordPress plug-in, has been installed in more than 2 million sites around the world, recently exposed that the plug-in has a high-risk vulnerability of XSS (cross-site scripting).
This XSS vulnerability in ACF allows unauthorized users to potentially steal sensitive information without the permission of the webmaster.
Malicious actors may exploit vulnerabilities in plug-ins to inject malicious scripts, such as redirects, advertisements, and other HTML payloads. If a user visits a tampered site, the user's device will be infected and execute a malicious script.
At present, officials have released an update of version 6.16 to fix the above vulnerabilities. If a webmaster is still using version 6.15 or earlier, CTOnews.com recommends upgrading as soon as possible.