WordPress Plugin Advanced Custom Fields (ACF) acf_abspath Parameter Remote File Include
WordPress Plugin Advanced Custom Fields (ACF) is prone to a remote file include vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to compromise the application and the underlying system other attacks are also possible. WordPress Plugin Advanced Custom Fields (ACF) version 3.5.1 is vulnerable prior versions may also be affected.