Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Duc Luong Tran

Researcher fromViettel Cyber Security
#48287of 53,635
5.3Total CVSS
Vulnerabilities · 1
PT-2024-33558
5.3
2024-10-16
WordPress · Advanced Custom Fields Pro · CVE-2024-49593
**Name of the Vulnerable Software and Affected Versions** Advanced Custom Fields (ACF) versions prior to 6.3.9 Secure Custom Fields versions prior to 6.3.6.3 **Description** The issue allows for the execution of a stored XSS payload when using the Field Group editor to edit one of the plugin's fields in Advanced Custom Fields (ACF) and Secure Custom Fields for WordPress. **Recommendations** For Advanced Custom Fields (ACF) versions prior to 6.3.9, update to version 6.3.9 or later. For Secure Custom Fields versions prior to 6.3.6.3, update to version 6.3.6.3 or later. As a temporary workaround, consider restricting access to the Field Group editor until a patch is applied.