Skip to main content
Loading…
    CVE-2025-12030 — The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4. This is due to insufficient capability checks in the update_item — CVE Database · The Intelligence Room