Unauthorized Data Modification in ACF Photo Gallery Field Plugin for WordPress
CVE-2023-3957
4.3MEDIUM
What is CVE-2023-3957?
The ACF Photo Gallery Field plugin for WordPress suffers from a security flaw that allows authenticated users with subscriber-level permissions or higher to exploit insufficient restrictions within the 'apg_profile_update' function. This vulnerability permits attackers to arbitrarily alter user meta values, which can potentially lead to unauthorized access or alterations of sensitive data, undermining the integrity of the site.
Affected Version(s)
ACF Photo Gallery Field * <= 1.9