{"id":"CVE-2020-13700","aliases":["GHSA-r345-x8hr-2r9p"],"url":"https://o3.security/vulnerability/CVE-2020-13700","summary":"acf-to-rest-api plugin insecure direct object reference (IDOR) via permalink manipulation","details":"An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.","published":"2020-06-24T15:15:11.853Z","modified":"2026-07-09T00:12:57.820790Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.13463,"percentile":0.96209,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"airesvsg/acf-to-rest-api","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/airesvsg/acf-to-rest-api"},{"type":"ADVISORY","url":"https://wordpress.org/plugins/acf-to-rest-api/#developers"},{"type":"EVIDENCE","url":"https://gist.github.com/mariuszpoplwski/4fbaab7f271bea99c733e3f2a4bafbb5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:12:57.820790Z"}}