Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's.
We have discovered 6,919 live websites that are affected by CVE-2024-45429.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 6,919 live websites (51.77% of Advanced Custom Fields install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 171 versions ( 92.93% of all versions) |
![]() | 2,536 websites |
![]() | 697 websites |
![]() | 670 websites |
![]() | 371 websites |
![]() | 343 websites |
![]() | 155 websites |
![]() | 155 websites |
![]() | 124 websites |
![]() | 109 websites |
![]() | 107 websites |
.com | 2,613 websites |
.org | 398 websites |
.fr | 346 websites |
.de | 282 websites |
.ru | 272 websites |
.co.uk | 256 websites |
.com.br | 171 websites |
.nl | 164 websites |
.net | 151 websites |
.it | 141 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *,*** | |
********.org | ![]() | **,*** | |
********.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
******************.org | ![]() | **,*** | |
********.com | ![]() | **,*** | |
************.org | ![]() | **,*** | |
********.nl | ![]() | **,*** | |
****.org | ![]() | **,*** | |
********.com | ![]() | **,*** |
FAQ