CVE-2024-37250: WordPress Advanced Custom Fields Pro plugin < 6.3.2 - Subscriber+ Broken Access Control vulnerability
Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37250?
CVE-2024-37250 is classified as a missing authorization vulnerability which can lead to unauthorized access due to incorrectly configured access control security levels.
How do I fix CVE-2024-37250?
To fix CVE-2024-37250, update the Advanced Custom Fields PRO plugin to version 6.3.2 or later to ensure proper access control configurations.
Which versions of Advanced Custom Fields PRO are affected by CVE-2024-37250?
CVE-2024-37250 affects all versions of Advanced Custom Fields PRO from n/a through 6.3.1.
What impact does CVE-2024-37250 have on WordPress websites?
CVE-2024-37250 can potentially allow attackers to exploit improperly configured access controls, leading to unauthorized actions on WordPress websites using the affected plugin.
Is CVE-2024-37250 still a threat if I have updated my plugin?
If you have updated the Advanced Custom Fields PRO plugin to version 6.3.2 or later, CVE-2024-37250 should no longer pose a threat.