Description
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
Remediation
References
Related Vulnerabilities
IBM RTC Cross-site Scripting (XSS) Vulnerability (CVE-2020-4691)
WordPress Plugin Really Simple Guest Post Local File Inclusion (1.0.6)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (1.2.05.20)
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.15)
WordPress Plugin aoringo TAG upper Cross-Site Scripting (0.1.6)