CVE-2023-40068: Advancedcustomfields Advanced Custom Fields
Medium severity, CVSS 5.4. EPSS: 2% chance of exploitation in the next 30 days.
Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
Affected products
- Advancedcustomfields Advanced Custom Fields: from 6.1.0, up to and including 6.1.7
Published 2023-08-21. Last modified 2026-06-17.