CVE-2024-49593

In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF, then you can follow the process shown at the advancedcustomfields.com blog URL within the References section below.


We have discovered 3,851 live websites that are affected by CVE-2024-49593.

Run a Free Instant Scan




Affected Software

Product  Advanced Custom Fields
Category Wordpress Plugins
Vulnerable Domains3,851 live websites (44% of Advanced Custom Fields install base)
Vulnerable Versions
  • from 0 through 6.3.9
Vulnerable Versions Count107 versions ( 81% of all versions)



Details

  • Published - Oct 17, 2024
  • Updated - Nov 18, 2024

Website Distribution by Country

Number of websites using CVE-2024-49593
United States1,140 websites



France321 websites
Germany312 websites
GB290 websites
Russia222 websites
Canada124 websites
Netherlands114 websites
Italy110 websites
Japan82 websites
Switzerland81 websites

Website Distribution by TLD

Number of websites using CVE-2024-49593
.com1,478 websites
.org240 websites
.de184 websites
.ru168 websites
.fr157 websites
.co.uk149 websites
.nl95 websites
.net77 websites
.com.au76 websites
.it75 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-49593

Top websites that are affected by CVE-2024-49593. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
******************.org United States**,***
********.com United States**,***
****.org United States**,***
********.com United States**,***
****.org United States**,***
**************.com United States**,***
*******.edu United States**,***
*********************.com United States**,***
**************.com United States***,***
See full domain list

FAQ

A total of 3,851 websites have been identified as vulnerable to CVE-2024-49593, based on global website indexing conducted by WebTechSurvey.
The Advanced Custom Fields is affected by the CVE-2024-49593 vulnerability.
Advanced Custom Fields versions up to 6.3.9 are vulnerable to CVE-2024-49593.
CVE-2024-49593 is resolved in version 6.3.9 of Advanced Custom Fields.