In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF, then you can follow the process shown at the advancedcustomfields.com blog URL within the References section below.
We have discovered 3,851 live websites that are affected by CVE-2024-49593.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,851 live websites (44% of Advanced Custom Fields install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 107 versions ( 81% of all versions) |
| 1,140 websites | |
| 321 websites | |
| 312 websites | |
| 290 websites | |
| 222 websites | |
| 124 websites | |
| 114 websites | |
| 110 websites | |
| 82 websites | |
| 81 websites |
| .com | 1,478 websites |
| .org | 240 websites |
| .de | 184 websites |
| .ru | 168 websites |
| .fr | 157 websites |
| .co.uk | 149 websites |
| .nl | 95 websites |
| .net | 77 websites |
| .com.au | 76 websites |
| .it | 75 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| ******************.org | **,*** | ||
| ********.com | **,*** | ||
| ****.org | **,*** | ||
| ********.com | **,*** | ||
| ****.org | **,*** | ||
| **************.com | **,*** | ||
| *******.edu | **,*** | ||
| *********************.com | **,*** | ||
| **************.com | ***,*** |
FAQ