CVE-2024-4565 Vulnerability Details

  /     /     /  

CVE-2024-4565 Metadata Quick Info

CVE Published: 20/06/2024 | CVE Updated: 01/08/2024 | CVE Year: 2024
Source: WPScan | Vendor: Unknown | Product: Advanced Custom Fields (ACF)
Status : PUBLISHED

CVE-2024-4565 Description

The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: CWE-284 Improper Access Control
Source: Unknown

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).