CVE-2024-45429

Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's.


We have discovered 3,725 live websites that are affected by CVE-2024-45429.

Run a Free Instant Scan




Affected Software

Product  Advanced Custom Fields
Category Wordpress Plugins
Vulnerable Domains3,725 live websites (42% of Advanced Custom Fields install base)
Vulnerable Versions
  • from 0 through 6.3.5
Vulnerable Versions Count104 versions ( 79% of all versions)



Details

  • Published - Sep 4, 2024
  • Updated - Mar 25, 2025

Website Distribution by Country

Number of websites using CVE-2024-45429
United States1,103 websites



France309 websites
Germany301 websites
GB286 websites
Russia215 websites
Canada123 websites
Netherlands113 websites
Italy108 websites
Switzerland81 websites
Sweden77 websites

Website Distribution by TLD

Number of websites using CVE-2024-45429
.com1,437 websites
.org231 websites
.de176 websites
.ru163 websites
.fr148 websites
.co.uk143 websites
.nl94 websites
.com.au74 websites
.it73 websites
.net72 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-45429

Top websites that are affected by CVE-2024-45429. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
******************.org United States**,***
********.com United States**,***
****.org United States**,***
********.com United States**,***
****.org United States**,***
**************.com United States**,***
*******.edu United States**,***
*********************.com United States**,***
**************.com United States***,***
See full domain list

FAQ

A total of 3,725 websites have been identified as vulnerable to CVE-2024-45429, based on global website indexing conducted by WebTechSurvey.
The Advanced Custom Fields is affected by the CVE-2024-45429 vulnerability.
Advanced Custom Fields versions up to and including 6.3.5 are vulnerable to CVE-2024-45429.