I’ve received a mail about Patchstack when they originally reported it. However, their site broke when I tried to see the details of the report so I never got around to looking at it. I’ll be giving it another try this weekend.
Hi, I too have picked up a vulnerability in my latest scan on one of my sites.
WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 – Broken Access Control vulnerability
Will a fix be updated soon?
@charactercreates this is the same report indeed. I’ve been able to look at the report properly now. The issue has no further connections to access related to WordPress itself, just to calm everyone down.
The report is about communications with the Font Awesome API, which is needed to search for available icons when using the field.
I’ll be able to look into a potential fix this weekend.
@nvkc Correct, and I’m working on it. Although I do not fully agree with the new report; it states that Contributors can make calls to the Font Awesome API. But that is fully intended, as a contributor can come across a FA field in which case it needs access…