CVE-2024-37250

WordPress Advanced Custom Fields Pro plugin < 6.3.2 - Subscriber+ Broken Access Control vulnerability

Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.


We have discovered 3,561 live websites that are affected by CVE-2024-37250.

Run a Free Instant Scan




Affected Software

Product  Advanced Custom Fields
Category Wordpress Plugins
Vulnerable Domains3,561 live websites (40% of Advanced Custom Fields install base)
Vulnerable Versions
  • from 0 through 6.3.1
Vulnerable Versions Count100 versions ( 76% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Nov 1, 2024
  • Updated - Apr 28, 2026

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2024-37250
United States1,063 websites



France293 websites
Germany284 websites
GB275 websites
Russia206 websites
Canada119 websites
Netherlands109 websites
Italy104 websites
Switzerland80 websites
Sweden76 websites

Website Distribution by TLD

Number of websites using CVE-2024-37250
.com1,385 websites
.org215 websites
.de163 websites
.ru157 websites
.fr141 websites
.co.uk139 websites
.nl90 websites
.com.au72 websites
.net71 websites
.it69 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-37250

Top websites that are affected by CVE-2024-37250. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
********.com United States**,***
****.org United States**,***
********.com United States**,***
****.org United States**,***
**************.com United States**,***
*******.edu United States**,***
*********************.com United States**,***
**************.com United States***,***
*********.com GB***,***
See full domain list

FAQ

CVE-2024-37250 is Missing Authorization in Advanced Custom Fields
A total of 3,561 websites have been identified as vulnerable to CVE-2024-37250, based on global website indexing conducted by WebTechSurvey.
The Advanced Custom Fields is affected by the CVE-2024-37250 vulnerability.
Advanced Custom Fields versions up to and including 6.3.1 are vulnerable to CVE-2024-37250.