5.3

CVE-2024-49593

Advanced Custom Fields <= 6.3.8 & Secure Custom Fields <= 6.3.6.2 - Authenticated (Admin+) Stored Cross-Site Scripting

In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF, then you can follow the process shown at the advancedcustomfields.com blog URL within the References section below.
Mögliche Gegenmaßnahme
Advanced Custom Fields: Update to version 6.3.9, or a newer patched version
Advanced Custom Fields Pro: Update to version 6.3.9, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Advanced Custom Fields
Version *-6.3.6
Version 6.3.7
Version 6.3.8
SystemWordPress Plugin
Produkt Advanced Custom Fields Pro
Version *-6.3.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.397
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://wordpress.org/plugins/advanced-custom-fields/#developers
https://www.advancedcustomfields.com/changelog/
https://www.advancedcustomfields.com/blog/installing-and-upgrading-to-the-latest-version-of-acf/
https://x.com/wp_acf/status/1845190372764401908
https://www.wordfence.com/threat-intel/vulnerabilities/id/b3552de0-3e0b-4529-a757-a31c69a06122
Third Party Advisory