S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-13700 Scanner

Detects 'Insecure Direct Object References (IDOR)' vulnerability in acf-to-rest-api plugin for Wordpress affects v. through 3.1.0.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-13700
7.5
CVSS

An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The acf-to-rest-api plugin is a popular add-on for Wordpress that allows website owners to easily expose their Advanced Custom Fields (ACF) data via the REST API. This makes it easy for developers to query and work with custom fields in their applications without the need for complex SQL queries or custom code. With this plugin, website owners can easily extend the functionality of their Wordpress site and offer a more personalized, sophisticated user experience.

CVE-2020-13700 is a recently discovered vulnerability in the acf-to-rest-api plugin, which allows an attacker to exploit an insecure direct object reference via permalinks manipulation. This vulnerability can result in unauthorized access to sensitive data, such as login and password values, which can be found in the wp_options table. This security flaw can be dangerous, as it allows attackers to gain access to private information and potentially compromise the entire website.

If exploited, the vulnerability CVE-2020-13700 can lead to a number of negative outcomes, including data theft, unauthorized access to sensitive information, and even website downtime due to damage caused by a cyber-attack. Such incidents can be incredibly damaging for businesses and website owners, leading to loss of revenue, tarnished reputations, and other potentially long-term effects.

At s4e.io, we offer a powerful platform that provides in-depth analysis of digital assets and identifies vulnerabilities in real-time using advanced technologies like machine learning. With our pro features, you can easily and quickly learn about vulnerabilities in your digital assets, allowing you to take action before any damage is done. So, don't wait - sign up today and protect your website from potential threats!

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners should take the following precautions:

  • Update the acf-to-rest-api plugin to the latest version.
  • Enable automatic updates for all Wordpress plugins to ensure that security patches are applied as soon as they become available.
  • Regularly monitor website logs and audit trails for any suspicious activity.
  • Use complex passwords and two-factor authentication to protect login credentials.
  • Implement a Web Application Firewall (WAF) to protect against malicious traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-13700 scanner - Insecure Direct Object References (IDOR) vulnerability in acf-to-rest-api plugin for Wordpress | S4E