Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution
Published Nov 15, 2024
6.6
MEDIUMCVSS 3.1
EPSS 0.43%
Description
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.
Affected products
- Vendor n/a Product Advanced Custom Fields Pro Defaultunaffected
- Version 0StatusaffectedConstraints<6.3.9
- Version
- Vendor n/a Product Secure Custom Fields Defaultunaffected
- Version 0StatusaffectedConstraints<6.3.6.3
- Version 6.3.7StatusaffectedConstraints<6.3.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Advanced Custom Fields Pro | unaffected |
| |||||||||
| n/a | Secure Custom Fields | unaffected |
|
- < 6.3.9
- < 6.3.9
-
- Version 0StatusaffectedConstraints<6.3.9
- Version
-
- Version 0StatusaffectedConstraints<6.3.6.3
- Version 6.3.7StatusaffectedConstraints<6.3.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Wpengine | Advanced Custom Field Pro | unaffected |
| |||||||||
| Wpengine | Advanced Custom Fields | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (1)
- https://wpscan.com/vulnerability/dd3cc8d8-4dff-47f9-b036-5d09f2c7e5f2/ exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://wpscan.com/vulnerability/dd3cc8d8-4dff-47f9-b036-5d09f2c7e5f2/ | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.