« Volver al listado

CVE-2023-40068

Estado: ModificadaMedia (5.4)—

Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-40068",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-40068",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-04T17:57:15.209007Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "WP Engine",
          "product": "Advanced Custom Fields",
          "versions": [
            {
              "status": "affected",
              "version": "versions 6.1.0 to 6.1.7"
            }
          ]
        },
        {
          "vendor": "WP Engine",
          "product": "Advanced Custom Fields Pro",
          "versions": [
            {
              "status": "affected",
              "version": "versions 6.1.0 to 6.1.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-08-21T09:15:10.430",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN98946408/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://wordpress.org/plugins/advanced-custom-fields/",
      "tags": [
        "Product"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.advancedcustomfields.com/",
      "tags": [
        "Product"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.advancedcustomfields.com/blog/acf-6-1-8/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN98946408/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wordpress.org/plugins/advanced-custom-fields/",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.advancedcustomfields.com/",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.advancedcustomfields.com/blog/acf-6-1-8/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege."
    }
  ],
  "lastModified": "2026-06-17T06:16:01.377",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:-:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EF03DA3-87E4-4449-BE67-43FEBE09952B",
              "versionEndIncluding": "6.1.7",
              "versionStartIncluding": "6.1.0"
            },
            {
              "criteria": "cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:pro:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5706ED3-7C74-487F-B198-A0EB7FAE9DD3",
              "versionEndIncluding": "6.1.7",
              "versionStartIncluding": "6.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}