WP Engine Vulnerabilities and Affected Products
Vulnerabilities associated with Advanced Custom Fields.
Products
Clear product- Advanced Custom Fields3 vulnerabilities
- Advanced Custom Fields Pro3 vulnerabilities
- Advanced Custom Fields (ACF)1 vulnerability
- Faust.js1 vulnerability
- Gutenberg Blocks – ACF Blocks Suite1 vulnerability
- PHP Compatibility Checker1 vulnerability
- WP Migrate Lite1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-45429MEDIUM | Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's. CWE-79Sep 4, 2024 | CVSS6.1v3.1 | EPSS0.419% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-40068MEDIUM | Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege. CWE-79Aug 21, 2023 | CVSS5.4v3.1 | EPSS1.48% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30777HIGH | WordPress Advanced Custom Fields / Advanced Custom Fields PRO plugins <= 6.1.5 vulnerable to Cross Site Scripting (XSS)Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions. | CVSS7.1v3.1 | EPSS38.8% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |