CVE-2024-9529
Published: Nov 15, 2024
Modified: Nov 15, 2024
Description
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Secure Custom Fields | affected 6.3.7 - < 6.3.9 |
Unknown | Secure Custom Fields | affected 0 - < 6.3.6.3 |
Unknown | Advanced Custom Fields Pro | affected 0 - < 6.3.9 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now