Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's.
We have discovered 3,725 live websites that are affected by CVE-2024-45429.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,725 live websites (42% of Advanced Custom Fields install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 104 versions ( 79% of all versions) |
| 1,103 websites | |
| 309 websites | |
| 301 websites | |
| 286 websites | |
| 215 websites | |
| 123 websites | |
| 113 websites | |
| 108 websites | |
| 81 websites | |
| 77 websites |
| .com | 1,437 websites |
| .org | 231 websites |
| .de | 176 websites |
| .ru | 163 websites |
| .fr | 148 websites |
| .co.uk | 143 websites |
| .nl | 94 websites |
| .com.au | 74 websites |
| .it | 73 websites |
| .net | 72 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| ******************.org | **,*** | ||
| ********.com | **,*** | ||
| ****.org | **,*** | ||
| ********.com | **,*** | ||
| ****.org | **,*** | ||
| **************.com | **,*** | ||
| *******.edu | **,*** | ||
| *********************.com | **,*** | ||
| **************.com | ***,*** |
FAQ