Extension WordPress
Vulnérabilités ACF Photo Gallery Field
Cette page rassemble les failles publiées pour ACF Photo Gallery Field, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ACF Photo Gallery Field
4 fiches
ACF Photo Gallery Field <= 3.0 – Missing Authorization to Authenticated (Subscriber+) Attachment Metadata Modification
The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "acf_photo_gallery_edit_save" function in all versions up to, and including, 3.0. This makes it possible for…
*-3.0
3.1
18/02/2026
ACF Photo Gallery Field <= 2.6 – Missing Authorization in apgf_update_donation
The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the apgf_update_donation function in versions up to and including 2.6. This makes it possible for authenticated…
*-2.6
2.7
30/01/2024
ACF Photo Gallery Field <= 1.9 – Authenticated (Subscriber+) Arbitrary Usermeta Update
The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in versions up to, and including, 1.9. This makes it possible for authenticated attackers,…
*-1.9
2.0
26/07/2023
ACF Photo Gallery Field <= 1.7.4 – Reflected Cross-Site Scripting
The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issue
*-1.7.4
1.7.5
20/12/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.