CVE-2025-54940
Severity CVSS v4.0:
MEDIUM
Type:
CWE-94
Code Injection
Publication date:
08/08/2025
Last modified:
08/08/2025
Description
An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.
Impact
Base Score 4.0
4.60
Severity 4.0
MEDIUM
Base Score 3.x
3.40
Severity 3.x
LOW



