nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-9529 CVE-2024-9529
MEDIUM
Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution
Record summary
CVE-2024-9529 has a selected CVSS score of 6.6 (medium).
Description
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 15, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Advanced Custom Fields ProDefault status: unaffected | CVE List | Before 6.3.9 | affected |
Secure Custom FieldsDefault status: unaffected | CVE List | 6.3.7 to < 6.3.9 | affected |
| Before 6.3.6.3 | affected | ||
advanced_custom_field_proBrowse wpengine / advanced_custom_field_proDefault status: unaffected | CVE List | Before 6.3.9 | affected |
advanced_custom_fieldsBrowse wpengine / advanced_custom_fieldsDefault status: unaffected | CVE List | Before 6.3.6.3 | affected |
| 6.3.7 to < 6.3.9 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/dd3cc8d8-4dff-47f9-b036-5d09f2c7e5f2