• Resolved kajori

    (@kajori)


    Hi Team,

    This is regarding the ACF forms that is present in wordpress admin panel.

    While creating a new field group there are two fields in the form namely field label and field name. These two field accepts scripts also and executes it. Which makes it vulnerable to XSS attacks.

    Is there anything that we can do to prevent it. Can we implement any validation via hook or anything that can stop this?

    • This topic was modified 5 months, 3 weeks ago by kajori.
    • This topic was modified 5 months, 3 weeks ago by kajori.
    • This topic was modified 5 months, 3 weeks ago by James Huff.
Viewing 1 replies (of 1 total)
  • Hi there!

    ACF Support Team here. This forum is generally used by ACF users to help each other out.

    However, we would love to continue investigating and troubleshooting this issue, please can you create a ticket using our ?support form and we can look into it further.

Viewing 1 replies (of 1 total)
  • You must be logged in to reply to this topic.