CVE-2024-45429

Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's.


We have discovered 6,919 live websites that are affected by CVE-2024-45429.

Test my site




Affected Software

Product  Advanced Custom Fields
Category Wordpress Plugins
Vulnerable Domains6,919 live websites (51.77% of Advanced Custom Fields install base)
Vulnerable Versions
  • from 0 through 6.3.5
Vulnerable Versions Count171 versions ( 92.93% of all versions)



Details

  • Published - Sep 4, 2024
  • Updated - Sep 5, 2024

CVE-2024-45429 usage by Country

United States2,536 websites



Germany697 websites
France670 websites
GB371 websites
Russia343 websites
Italy155 websites
Netherlands155 websites
Switzerland124 websites
Cyprus109 websites
Brazil107 websites

CVE-2024-45429 usage by TLD

.com2,613 websites
.org398 websites
.fr346 websites
.de282 websites
.ru272 websites
.co.uk256 websites
.com.br171 websites
.nl164 websites
.net151 websites
.it141 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-45429

Top websites that are affected by CVE-2024-45429. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
********.org United States**,***
********.com United States**,***
***************.com United States**,***
******************.org United States**,***
********.com United States**,***
************.org United States**,***
********.nl United States**,***
****.org United States**,***
********.com United States**,***
See full domain list

FAQ

A total of 6,919 websites have been identified as vulnerable to CVE-2024-45429, discovered through global website indexing conducted by WebTechSurvey.
Advanced Custom Fields is susceptible to CVE-2024-45429 vulnerability.
Advanced Custom Fields versions before, and including, 6.3.5 are vulnerable to CVE-2024-45429.