CVE-2020-36172: Advancedcustomfields Advanced Custom Fields

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.

Affected products

Published 2021-01-06. Last modified 2026-06-17.