The Advanced Custom Fields: Font Awesome Field plugin, versions <= 6.1.1, contains a Broken Access Control vulnerability. This vulnerability, classified as MEDIUM severity with a CVSS score of 4.3, could allow unauthorized access to sensitive information or functionality. Users of this plugin should be aware of the potential risks and take necessary actions to mitigate them. The CVE record was published o [truncated]
A stored cross-site scripting (XSS) vulnerability exists in the Advanced Custom Fields: Font Awesome Field WordPress plugin, affecting versions up to and including 5.0.2. The vulnerability stems from improper neutralization of input during web page generation (CWE-79). An attacker with low privileges can inject malicious scripts that execute in the context of other users' browsers, potentially leading to [truncated]