Sensitive Data Exposure in ACF to REST API Plugin by airesvsg
CVE-2025-62979

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 October 2025

What is CVE-2025-62979?

An insertion of sensitive information into sent data vulnerability has been identified in the ACF to REST API plugin by airesvsg. This flaw allows for the retrieval of embedded sensitive data, potentially exposing private user information and compromising data integrity. The issue affects versions from n/a up to and including 3.3.4, necessitating prompt updates to ensure data security and protect against unauthorized access.

Affected Version(s)

ACF to REST API <= n/a

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mohamad Fattyr | Patchstack Bug Bounty Program
.