Hello Denis,
We are writing to you today to notify you about a
security vulnerabilitysecurity vulnerability that was discovered in the
Advanced Custom Fields plugin. The plugin was detected on one or more of your websites.
If you have already updated Advanced Custom Fields to version 5.10, you can disregard this message.Some of the plugin's functions do not make proper capability checks, which allows low privilege users (such as subscribers) to view ACF data, move fields, and view field groups.
This affects versions prior to 5.10. We recommend updating this plugin immediately to the latest version.
The following is a list of affected sites:•
******
This vulnerability may exist in both live and staging environments. We recommend that both be checked and updated.
We detected this vulnerability on 8/27/2021 at 5:14 AM UTC, but due to the time difference between scanning for vulnerabilities and sending notifications, you may have already updated the vulnerable plugins.
Also, our test flags your site if it finds the plugin directory. So you will receive this notice if you deleted the plugin files but did not delete the plugin directory.
If you have any questions, please feel free to reach out to our Support team.
Thank you for being a Kinsta customer!