Skip to content

Comments

Broken Access Control Security Patch#76

Open
nickkeenan wants to merge 7 commits intoandersthorborg:masterfrom
nickkeenan:broken-access-control
Open

Broken Access Control Security Patch#76
nickkeenan wants to merge 7 commits intoandersthorborg:masterfrom
nickkeenan:broken-access-control

Conversation

@nickkeenan
Copy link

@nickkeenan nickkeenan commented Feb 22, 2026

Addresses CVE-2023-22676 (Broken Access Control, CVSS 3.1) Security issue

If this plugin is no longer maintained, I'm happy to create a maintained repository moving forward as this plugin is so helpful for my users. I have forked to https://github.com/nickkeenan/ACF-Image-Crop-Patched with bumped version numbers for anyone who needs a maintenance fix for this plugin.

Fix: Add capability check to perform_crop() - CVE-2023-22676
Addresses CVE-2023-22676 (Broken Access Control, CVSS 3.1)
- Adds user capability check to `perform_crop` AJAX action to prevent unauthorized users from cropping media library images
- Original report: https://patchstack.com/database/wordpress/plugin/acf-image-crop-add-on/vulnerability/wordpress-advanced-custom-fields-image-crop-add-on-plugin-1-4-12-broken-access-control
Broken Access Control Security Patch
Adds explicit class property declaration to resolve deprecated dynamic property creation warnings introduced in PHP 8.0 and fatal errors in PHP 8.2+.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant