First published: Fri Nov 15 2024(Updated: )
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Secure Custom Fields | <6.3.9<6.3.6.3 | |
Advanced Custom Fields Pro | <6.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9529 has a high severity rating due to its potential to allow arbitrary function execution.
To fix CVE-2024-9529, update the Secure Custom Fields plugin to version 6.3.9 or the Advanced Custom Fields Pro plugin to version 6.3.9.
CVE-2024-9529 affects Secure Custom Fields versions before 6.3.9 and Advanced Custom Fields Pro versions before 6.3.9.
The impact of CVE-2024-9529 includes the risk of arbitrary code execution which could lead to unauthorized access or data loss.
As of now, there is no confirmed information about active exploitation of CVE-2024-9529 in the wild.