Advanced Custom Fields

Vendor:

First CVE: Aug 22, 2019 · Active for 6 years

15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Advanced Custom Fields over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2019
6 years ago
Most Recent CVE
Nov 15, 2024
616 days ago

CVE Severity & Scoring

Advanced Custom Fields15 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (53.3%)
Unknown0 (0.0%)
Required7 (46.7%)
Privileges Required
Low8 (53.3%)
High1 (6.7%)
None6 (40.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.
May 10, 20236.153NOYES
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a defau
Aug 22, 20228.828NONO
The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Co
May 2, 20238.827NONO
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may all
Dec 13, 20217.526NONO
Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacke
Mar 31, 20226.523NONO
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which ma
Dec 13, 20216.523NONO
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which m
Dec 13, 20216.523NONO
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 throu
Jan 8, 20247.522NONO
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prev
Nov 15, 20246.620NONO
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site
Apr 22, 20216.120NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Advanced Custom Fields

Top CWEs

Versions

No cataloged versions.