Known vulnerabilities in Advanced Custom Fields Pro
Vendor:
Elliot Condon
Software:
Advanced Custom Fields Pro
Software CPE:
cpe:2.3:a:elliotcondon:advanced_custom_fields_pro:*:*:*:*:*:*:*:*
Total vulnerabilities:
5
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU96773 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-45429 |
CWE-79 | Low | 6.3.6 | 04.09.2024 |
SB2024090404 |
||
| #VU79807 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-40068 |
CWE-79 | Low | 6.1.8 | 21.08.2023 |
SB20230821231 |
||
| #VU76106 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-30777 |
CWE-79 | Medium | 5.12.6, 6.1.5 | 15.05.2023 |
SB2023051503 |
||
| #VU69193 - Unrestricted Upload of File with Dangerous Type CVE-2022-2594 |
CWE-434 | High | 5.12.3 | 09.11.2022 |
SB2022110964 |
||
| #VU61724 - Missing Authorization CVE-2022-23183 |
CWE-862 | Medium | 5.12.1 | 30.03.2022 |
SB2022033004 |