GHSA-r345-x8hr-2r9p
Dashboard / Vulnerabilities / GHSA-r345-x8hr-2r9p
Summary: acf-to-rest-api plugin insecure direct object reference (IDOR) via permalink manipulation
Details: An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a `wp-json/acf/v3/options/` request that reads sensitive information in the `wp_options` table, such as the login and pass values.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-13700, https://gist.github.com/mariuszpoplwski/4fbaab7f271bea99c733e3f2a4bafbb5, https://github.com/airesvsg/acf-to-rest-api, https://wordpress.org/plugins/acf-to-rest-api/#developers
Affected packages
Package
Name: airesvsg/acf-to-rest-api
Purl: pkg:composer/airesvsg/acf-to-rest-api
Affected ranges
Type: ECOSYSTEM
Events:
