CVE-2024-4565

Severity
6.5MEDIUM
EPSS
0.2%
top 59.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 20
Latest updateSep 2

Description

The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

4
OSV
protobuf vulnerabilities2025-09-02
OSV
protobuf vulnerabilities2025-07-09
GHSA
GHSA-6x2p-g636-5378: The Advanced Custom Fields (ACF) WordPress plugin before 62024-06-20
CVEList
Advanced Custom Fields < 6.3 - Contributor+ Custom Field Access2024-06-20
CVE-2024-4565 (MEDIUM CVSS 6.5) | The Advanced Custom Fields (ACF) Wo | cvebase.io