CVE-2024-4565: Advanced Custom Fields < 6.3 - Contributor+ Custom Field Access
The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4565?
CVE-2024-4565 is classified as a medium-severity vulnerability that allows unauthorized access to custom field values.
How do I fix CVE-2024-4565?
To fix CVE-2024-4565, update the Advanced Custom Fields and Advanced Custom Fields Pro plugins to version 6.3 or later.
What are the consequences of CVE-2024-4565?
Exploiting CVE-2024-4565 can lead to unauthorized exposure of custom field values across posts in WordPress.
Which versions of Advanced Custom Fields are affected by CVE-2024-4565?
Versions of Advanced Custom Fields and Advanced Custom Fields Pro before 6.3 are affected by CVE-2024-4565.
Is CVE-2024-4565 an exploit in other plugins?
CVE-2024-4565 specifically affects the Advanced Custom Fields plugin and its Pro version and does not directly signify an exploit in other plugins.