Cross-site Scripting Vulnerability in Advanced Custom Fields: Font Awesome Field by Justin Kruit
CVE-2026-49044

6.5MEDIUM

What is CVE-2026-49044?

A Cross-site Scripting (XSS) vulnerability exists in the Advanced Custom Fields: Font Awesome Field plugin, allowing attackers to execute malicious scripts within the user’s browser. This vulnerability impacts all versions from n/a up to 5.0.2, potentially enabling unauthorized access to user data and compromising site integrity. Attackers can exploit this flaw by injecting crafted input, which the application fails to properly neutralize during web page generation. Users are advised to update their installations to protect against possible exploitation.

Affected Version(s)

Advanced Custom Fields: Font Awesome Field <= 5.0.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

timomangcut | Patchstack Bug Bounty Program
.