Beebee Mini <= 1.2.0 - Unauthorized File Upload via ACF
medium
The Beebee Mini plugin for WordPress uses Advanced Custom Fields which has a file upload vulnerability in versions up to, and including, 5.12.2. This makes it possible for users without the upload_files capability, such as contributors, or unauthenticated users in cases where a frontend form is added to the site, to up...
- CVSS:
- 4.3
- Affected:
- up to 1.2.0
- Fixed in:
- 1.3.0
- Disclosed:
- Oct 3, 2022
CVE-2022-2594 on NVD →
Beebee Mini [beebee-mini] < 1.3.0
unknown
[en] The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrit...
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Aug 22, 2022
CVE-2022-2594 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database