AdvancedCustomFields / AdvancedCustomFields/acf
🚨 Potential Cross-site Scripting (XSS) - Stored
Nobody has claimed this yet.
- Dominant language
- PHP
- Stars
- 945
- Forks
- 197
- PR merge metrics
- No merged PRs in 30d
Description
👋 Hello, @elliotcondon, @cfoellmann, @moritzjacobs - a potential high severity Cross-site Scripting (XSS) - Stored vulnerability in your repository has been disclosed to us.
Next Steps
1️⃣ Visit https://huntr.dev/bounties/1-other-AdvancedCustomFields/acf for more advisory information.
2️⃣ Sign-up to validate or speak to the researcher for more assistance.
3️⃣ Propose a patch or outsource it to our community - whoever fixes it gets paid.
Confused or need more help?
-
Join us on our Discord and a member of our team will be happy to help! 🤗
-
Speak to a member of our team: @JamieSlome
This issue was automatically generated by huntr.dev - a bug bounty board for securing open source code.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the linked huntr.dev advisory for the vulnerability details; the issue does not identify a repository file, test, or entry point. Confirm the stored XSS behavior and define completion as the vulnerability no longer being reproducible, with appropriate regression coverage added.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100