wpengine Vulnerabilities and Affected Products
Vulnerabilities associated with Gutenberg Blocks – ACF Blocks Suite.
Products
Clear product- Advanced Custom Fields (ACF®)3 vulnerabilities
- advanced_custom_field_pro3 vulnerabilities
- Database Backup for WordPress3 vulnerabilities
- wpgraphql3 vulnerabilities
- advanced_custom_fields2 vulnerabilities
- Better Search Replace1 vulnerability
- better_search_replace1 vulnerability
- Gutenberg Blocks – ACF Blocks Suite1 vulnerability
- WP Migrate Lite – Migration Made Easy1 vulnerability
- wp_migrate1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-4974MEDIUM | Freemius SDK <= 2.4.2 - Missing Authorization ChecksThe Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable. CWE-862Oct 16, 2024 | CVSS6.3v3.1 | EPSS0.442% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |