Back to search
CVE-2020-13700
Published: Jun 24, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/airesvsg/acf-to-rest-api
x_refsource_MISC
https://wordpress.org/plugins/acf-to-rest-api/#developers
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now