CVE-2024-34761: Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Arbitrary Function Execution vulnerability
Vulnerability discovered by executing a planned security audit.
Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows Code Injection.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34761?
CVE-2024-34761 is categorized as a Code Injection vulnerability that can have a high impact on affected systems.
How do I fix CVE-2024-34761?
To remediate CVE-2024-34761, upgrade Advanced Custom Fields PRO to version 6.2.10 or higher.
Which versions are affected by CVE-2024-34761?
CVE-2024-34761 affects Advanced Custom Fields PRO versions prior to 6.2.10.
What type of vulnerability is CVE-2024-34761?
CVE-2024-34761 is an Improper Control of Generation of Code vulnerability, specifically known as Code Injection.
Who is the vendor for the software impacted by CVE-2024-34761?
The vendor for the affected software is WPENGINE, specifically the Advanced Custom Fields PRO plugin.