An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wordpress
Wordpress wordpress Wpengine Wpengine advanced Custom Fields |
|
Vendors & Products |
Wordpress
Wordpress wordpress Wpengine Wpengine advanced Custom Fields |
Fri, 08 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 08 Aug 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered. | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: jpcert
Published: 2025-08-08T04:34:02.380Z
Updated: 2025-08-08T16:11:14.551Z
Reserved: 2025-08-01T05:50:41.871Z
Link: CVE-2025-54940

Updated: 2025-08-08T16:11:10.475Z

Status : Awaiting Analysis
Published: 2025-08-08T05:15:32.317
Modified: 2025-08-08T20:30:18.180
Link: CVE-2025-54940

No data.