The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/430224c4-d6e3-4ca8-b1bc-b2229a9bcf12/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/430224c4-d6e3-4ca8-b1bc-b2229a9bcf12/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 09:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/430224c4-d6e3-4ca8-b1bc-b2229a9bcf12/ - Exploit, Third Party Advisory |
17 Jul 2024, 14:14
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:pro:wordpress:*:* cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:-:wordpress:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
First Time |
Advancedcustomfields advanced Custom Fields
Advancedcustomfields |
|
References | () https://wpscan.com/vulnerability/430224c4-d6e3-4ca8-b1bc-b2229a9bcf12/ - Exploit, Third Party Advisory | |
CWE | NVD-CWE-noinfo |
03 Jul 2024, 02:07
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
20 Jun 2024, 12:43
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
20 Jun 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-20 06:15
Updated : 2024-11-21 09:43
NVD link : CVE-2024-4565
Mitre link : CVE-2024-4565
CVE.ORG link : CVE-2024-4565
JSON object : View
Products Affected
advancedcustomfields
- advanced_custom_fields
CWE