Get the App
SLTechnology News&Howtos  ›  IT Information  › 

2 million sites are affected, WordPress plug-in ACF is exposed high-risk vulnerabilities

Shulou Source: shulou.com Published: 2023-11-24 16:40:59 10月03日 Update

CTOnews.com May 10 news, Advanced Custom Fields (ACF) is a frequently used WordPress plug-in, has been installed in more than 2 million sites around the world, recently exposed that the plug-in has a high-risk vulnerability of XSS (cross-site scripting).

This XSS vulnerability in ACF allows unauthorized users to potentially steal sensitive information without the permission of the webmaster.

Malicious actors may exploit vulnerabilities in plug-ins to inject malicious scripts, such as redirects, advertisements, and other HTML payloads. If a user visits a tampered site, the user's device will be infected and execute a malicious script.

At present, officials have released an update of version 6.16 to fix the above vulnerabilities. If a webmaster is still using version 6.15 or earlier, CTOnews.com recommends upgrading as soon as possible.

Tags: Vulnerabilities plug-ins malicious users scripts sites versions webmasters websites valid information global official advertising situation unpassed messages potential behavior devices Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Linux macOS Docker Shulou Information Xiaomi