CVE-2020-36172
06.01.2021, 15:15
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
Vendor | Product | Version |
---|---|---|
advancedcustomfields | advanced_custom_fields | 𝑥 < 5.8.12 |
𝑥
= Vulnerable software versions