CVE-2024-37249: WordPress Advanced Custom Fields Pro plugin < 6.3.2 - Contributor+ Broken Access Control vulnerability
Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37249?
CVE-2024-37249 is classified as a medium severity vulnerability due to its potential to exploit improperly configured access controls.
How do I fix CVE-2024-37249?
To fix CVE-2024-37249, update Advanced Custom Fields PRO to version 6.3.2 or later.
What versions are affected by CVE-2024-37249?
CVE-2024-37249 affects all versions of Advanced Custom Fields PRO from n/a to 6.3.1.
What type of vulnerability is CVE-2024-37249?
CVE-2024-37249 is a Missing Authorization vulnerability that allows exploitation due to incorrectly configured access control security levels.
Who is impacted by CVE-2024-37249?
Users of Advanced Custom Fields PRO from WPEngine and WordPress between versions n/a and 6.3.1 are impacted by CVE-2024-37249.