PT-2024-31626 · Unknown · Advanced Custom Fields Pro
Ryo Sotoyama
·
Published
2024-09-04
·
Updated
2024-09-13
·
CVE-2024-45429
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Advanced Custom Fields versions 6.3.5 and earlier
Advanced Custom Fields Pro versions 6.3.5 and earlier
Description:
A cross-site scripting issue exists, allowing an attacker with the
capability setting privilege to store an arbitrary script in the field label. This script may be executed on the web browser of a logged-in user with the same privilege as the attacker's.Recommendations:
For Advanced Custom Fields versions 6.3.5 and earlier, update to a version later than 6.3.5 to resolve the issue.
For Advanced Custom Fields Pro versions 6.3.5 and earlier, update to a version later than 6.3.5 to resolve the issue.
As a temporary workaround, consider restricting the
capability setting privilege to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Custom Fields Pro