CVE-2024-9529

Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution

The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.


We have discovered 3,851 live websites that are affected by CVE-2024-9529.

Run a Free Instant Scan




Affected Software

Product  Advanced Custom Fields
Category Wordpress Plugins
Vulnerable Domains3,851 live websites (44% of Advanced Custom Fields install base)
Vulnerable Versions
  • from 0 through 6.3.6.3
  • from 6.3.7 through 6.3.9
Vulnerable Versions Count107 versions ( 81% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Nov 15, 2024
  • Updated - Nov 15, 2024

Credits

  • Automattic Security Team (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-9529
United States1,140 websites



France321 websites
Germany312 websites
GB290 websites
Russia222 websites
Canada124 websites
Netherlands114 websites
Italy110 websites
Japan82 websites
Switzerland81 websites

Website Distribution by TLD

Number of websites using CVE-2024-9529
.com1,478 websites
.org240 websites
.de184 websites
.ru168 websites
.fr157 websites
.co.uk149 websites
.nl95 websites
.net77 websites
.com.au76 websites
.it75 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-9529

Top websites that are affected by CVE-2024-9529. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
******************.org United States**,***
********.com United States**,***
****.org United States**,***
********.com United States**,***
****.org United States**,***
**************.com United States**,***
*******.edu United States**,***
*********************.com United States**,***
**************.com United States***,***
See full domain list

FAQ

CVE-2024-9529 is Improper Control of Generation of Code ('Code Injection') in Advanced Custom Fields
A total of 3,851 websites have been identified as vulnerable to CVE-2024-9529, based on global website indexing conducted by WebTechSurvey.
The Advanced Custom Fields is affected by the CVE-2024-9529 vulnerability.
Advanced Custom Fields versions up to 6.3.9 are vulnerable to CVE-2024-9529.
CVE-2024-9529 is resolved in version 6.3.9 of Advanced Custom Fields.