CVE-2024-4565 Vulnerability Details
/
/
/
CVE-2024-4565 Metadata Quick Info
CVE Published: 20/06/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024
Source: WPScan |
Vendor: Unknown |
Product: Advanced Custom Fields (ACF)
Status : PUBLISHED
CVE-2024-4565 Description
The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: CWE-284 Improper Access Control
Source: Unknown
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).