Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.
We have discovered 3,518 live websites that are affected by CVE-2024-34762.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,518 live websites (40% of Advanced Custom Fields install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 98 versions ( 74% of all versions) |
| 1,057 websites | |
| 290 websites | |
| 280 websites | |
| 273 websites | |
| 204 websites | |
| 119 websites | |
| 109 websites | |
| 102 websites | |
| 80 websites | |
| 76 websites |
| .com | 1,373 websites |
| .org | 213 websites |
| .de | 163 websites |
| .ru | 156 websites |
| .fr | 140 websites |
| .co.uk | 137 websites |
| .nl | 90 websites |
| .com.au | 72 websites |
| .net | 69 websites |
| .it | 68 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| ********.com | **,*** | ||
| ****.org | **,*** | ||
| ********.com | **,*** | ||
| ****.org | **,*** | ||
| **************.com | **,*** | ||
| *******.edu | **,*** | ||
| *********************.com | **,*** | ||
| **************.com | ***,*** | ||
| *********.com | ***,*** |
FAQ