The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/dd3cc8d8-4dff-47f9-b036-5d09f2c7e5f2/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
11 Jun 2025, 13:58
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:free:wordpress:*:* cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:pro:wordpress:*:* |
|
First Time |
Advancedcustomfields advanced Custom Fields
Advancedcustomfields |
|
CWE | NVD-CWE-noinfo | |
References | () https://wpscan.com/vulnerability/dd3cc8d8-4dff-47f9-b036-5d09f2c7e5f2/ - Exploit, Third Party Advisory |
15 Nov 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.6 |
15 Nov 2024, 13:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Nov 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-15 07:15
Updated : 2025-06-11 13:58
NVD link : CVE-2024-9529
Mitre link : CVE-2024-9529
CVE.ORG link : CVE-2024-9529
JSON object : View
Products Affected
advancedcustomfields
- advanced_custom_fields
CWE