Known CVE
WordPress acf-to-rest-api <=3.1.0 - Insecure Direct Object Reference
WordPress acf-to-rest-ap through 3.1.0 allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that can read sensitive information in the wp_options table such as the login and pass values.
CVE-2020-13700
High2020CVSS 7.5CWE-639
cve2020 · wordpress · plugin · acf_to_rest_api_project · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website