CVE-2024-4565
Advanced Custom Fields < 6.3 - Contributor+ Custom Field Access
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access
El complemento Advanced Custom Fields (ACF) WordPress anterior a 6.3, el complemento de Advanced Custom Fields Pro WordPress anterior a 6.3 le permite mostrar valores de campo personalizados para cualquier publicación mediante un código corto sin verificar el acceso correcto
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to arbitrary custom field access in all versions up to, and including, 6.2.10. This is due to the plugin not properly restricting what post meta can be displayed through the plugin's shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve potentially sensitive information from custom fields.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-05-06 CVE Reserved
- 2024-05-30 CVE Published
- 2024-07-18 EPSS Updated
- 2024-08-01 First Exploit
- 2024-08-29 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/430224c4-d6e3-4ca8-b1bc-b2229a9bcf12 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Advanced Custom Fields (ACF) Search vendor "Unknown" for product "Advanced Custom Fields (ACF)" | < 6.3 Search vendor "Unknown" for product "Advanced Custom Fields (ACF)" and version " < 6.3" | en |
Affected
| ||||||
Unknown Search vendor "Unknown" | Advanced Custom Fields Pro Search vendor "Unknown" for product "Advanced Custom Fields Pro" | < 6.3 Search vendor "Unknown" for product "Advanced Custom Fields Pro" and version " < 6.3" | en |
Affected
|