Lucene search

K
cvelistWPScanCVELIST:CVE-2024-4565
HistoryJun 20, 2024 - 6:00 a.m.

CVE-2024-4565 Advanced Custom Fields < 6.3 - Contributor+ Custom Field Access

2024-06-2006:00:02
WPScan
www.cve.org
4
wordpress
plugin
security

0.0004 Low

EPSS

Percentile

9.2%

The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Advanced Custom Fields (ACF)",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThan": "6.3"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "Unknown",
    "product": "Advanced Custom Fields Pro",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThan": "6.3"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

0.0004 Low

EPSS

Percentile

9.2%

Related for CVELIST:CVE-2024-4565