WordPress Advanced Custom Fields PRO Plugin <= 6.3.8 is vulnerable to Cross Site Scripting (XSS)
Advanced Custom Field Pro
Minimum safe version
6.3.9
Update to 6.3.9 or later to address 19 fixable vulnerabilities
Advanced Custom Fields <= 6.3.8 & Secure Custom Fields <= 6.3.6.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Advanced Custom Fields <= 6.3.8 - Authenticated (Admin+) Limited Arbitrary Function Call
CVE-2024-45429
CVE-2024-37251
CVE-2024-37250
CVE-2024-37249
CVE-2024-4565
CVE-2024-34761
CVE-2024-34762
Advanced Custom Fields < 6.2.5 - Contributor+ Stored Cross-Site Scripting via Custom Field
WordPress Advanced Custom Fields PRO Plugin < 6.2.5 is vulnerable to Cross Site Scripting (XSS)
Advanced Custom Fields PRO 6.1 - 6.1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
WordPress Advanced Custom Fields PRO Plugin 6.1-6.1.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-1196
CVE-2023-30777
WordPress Advanced Custom Fields PRO Plugin < 5.11 is vulnerable to Broken Access Control
CVE-2022-2594
CVE-2022-23183
CVE-2021-24241