PT-2024-31626 · Unknown · Advanced Custom Fields Pro

Ryo Sotoyama

·

Published

2024-09-04

·

Updated

2024-09-13

·

CVE-2024-45429

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Advanced Custom Fields versions 6.3.5 and earlier Advanced Custom Fields Pro versions 6.3.5 and earlier
Description: A cross-site scripting issue exists, allowing an attacker with the capability setting privilege to store an arbitrary script in the field label. This script may be executed on the web browser of a logged-in user with the same privilege as the attacker's.
Recommendations: For Advanced Custom Fields versions 6.3.5 and earlier, update to a version later than 6.3.5 to resolve the issue. For Advanced Custom Fields Pro versions 6.3.5 and earlier, update to a version later than 6.3.5 to resolve the issue. As a temporary workaround, consider restricting the capability setting privilege to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-45429

Affected Products

Advanced Custom Fields Pro