## FULL DISCLOSURE #Product : Advanced Custom Fields #Exploit Author : Rahul Pratap Singh #Version : 4.4.7 #Home page Link :https://wordpress.org/plugins/advanced-custom-fields/ #Website : https://0x62626262.wordpress.com #Linkedin : https://in.linkedin.com/in/rahulpratapsingh94 #Date : 1/5/2016 Authenticated XSS Vulnerability: ---------------------------------------- Description: ---------------------------------------- "type, label, name and field" parameters are not sanitized that leads to XSS. ---------------------------------------- Vulnerable Code: ---------------------------------------- File Name: testfiles/advanced-custom-fields/core/views/meta_box_fields.php Found at line:97