CVE-2024-9529
MEDIUMDescription
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.
Is your site exposed to CVE-2024-9529?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| advancedcustomfields | advanced_custom_fields |
| advancedcustomfields | advanced_custom_fields |
References
Frequently Asked Questions
What is CVE-2024-9529? +
How severe is CVE-2024-9529? +
What products are affected by CVE-2024-9529? +
How do I check if I'm vulnerable to CVE-2024-9529? +
Related Vulnerabilities
The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to …
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in …
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom …