CVE Database
/

CVE-2024-9529

Back to search

CVE-2024-9529

Published: Nov 15, 2024

Modified: Nov 15, 2024

PUBLISHED

Description

The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.

VendorProductVersions

Unknown

Secure Custom Fields

affected
6.3.7 - < 6.3.9

Unknown

Secure Custom Fields

affected
0 - < 6.3.6.3

Unknown

Advanced Custom Fields Pro

affected
0 - < 6.3.9

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now