Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.
We have discovered 3,561 live websites that are affected by CVE-2024-37250.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,561 live websites (40% of Advanced Custom Fields install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 100 versions ( 76% of all versions) |
| 1,063 websites | |
| 293 websites | |
| 284 websites | |
| 275 websites | |
| 206 websites | |
| 119 websites | |
| 109 websites | |
| 104 websites | |
| 80 websites | |
| 76 websites |
| .com | 1,385 websites |
| .org | 215 websites |
| .de | 163 websites |
| .ru | 157 websites |
| .fr | 141 websites |
| .co.uk | 139 websites |
| .nl | 90 websites |
| .com.au | 72 websites |
| .net | 71 websites |
| .it | 69 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| ********.com | **,*** | ||
| ****.org | **,*** | ||
| ********.com | **,*** | ||
| ****.org | **,*** | ||
| **************.com | **,*** | ||
| *******.edu | **,*** | ||
| *********************.com | **,*** | ||
| **************.com | ***,*** | ||
| *********.com | ***,*** |
FAQ