WP Plugin Advanced Custom Fields Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-20986 - Vulnerability Database
WP Plugin Advanced Custom Fields Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-20986
Medium
Reference:
CVE-2018-20986
Title:
WP Plugin Advanced Custom Fields Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.