+ 30 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-9529
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8 |
Control incorrecto de la generación de código (inyección de código) |
Media
6,6
|
< 6.3.8
|
6.3.8 |
2024-10-07 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8 |
— |
Desconocido
|
< 6.3.8
|
6.3.8 |
2024-10-07 |
✓ corregido en la última versión
|
|
CVE-2024-45429
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 6.3.6
|
6.3.6 |
2024-09-04 |
✓ corregido en la última versión
|
|
CVE-2024-4565
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.0 |
Control de acceso incorrecto |
Media
6,5
|
< 6.3.0
|
6.3.0 |
2024-05-30 |
✓ corregido en la última versión
|
|
CVE-2023-6701
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 6.2.5
|
6.2.5 |
2024-01-17 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5 |
— |
Desconocido
|
< 6.2.5
|
6.2.5 |
2024-01-16 |
✓ corregido en la última versión
|
|
CVE-2023-40068
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 6.1.0 - <= 6.1.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
6.1.0–6.1.7
|
6.1.7 |
2023-08-21 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8 |
— |
Desconocido
|
< 6.1.8
|
6.1.8 |
2023-08-03 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8 |
— |
Desconocido
|
< 6.1.8
|
6.1.8 |
2023-08-03 |
✓ corregido en la última versión
|
|
CVE-2023-30777
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 6.1.6
|
6.1.6 |
2023-05-10 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6 |
— |
Desconocido
|
< 6.1.6
|
6.1.6 |
2023-05-04 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5 |
— |
Desconocido
|
< 5.12.5
|
5.12.5 |
2023-04-04 |
✓ corregido en la última versión
|
|
CVE-2023-1196
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5 |
Deserialización de datos no confiables |
Alta
8,8
|
< 5.12.5
|
5.12.5 |
2023-04-03 |
✓ corregido en la última versión
|
|
CVE-2022-40696
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 3.1.1 - <= 6.0.2 |
Exposición de información sensible a un actor no autorizado |
Baja
3,7
|
3.1.1–6.0.2
|
6.0.2 |
2022-10-18 |
✓ corregido en la última versión
|
|
CVE-2022-2594
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.3 |
Carga de archivos sin restricción de tipo peligroso |
Alta
8,8
|
< 5.12.3
|
5.12.3 |
2022-07-14 |
✓ corregido en la última versión
|
|
CVE-2022-23183
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1 |
Falta de control de autorización |
Media
6,5
|
< 5.12.1
|
5.12.1 |
2022-03-30 |
✓ corregido en la última versión
|
|
CVE-2021-20865
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11 |
Falta de control de autorización |
Alta
7,5
|
< 5.11
|
5.11 |
2021-12-02 |
✓ corregido en la última versión
|
|
CVE-2021-20866
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11 |
Falta de control de autorización |
Media
6,5
|
< 5.11
|
5.11 |
2021-12-02 |
✓ corregido en la última versión
|
|
CVE-2021-20867
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1 |
Falta de control de autorización |
Media
6,5
|
< 5.12.1
|
5.12.1 |
2021-12-02 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.10 |
— |
Desconocido
|
< 5.10
|
5.10 |
2021-08-25 |
✓ corregido en la última versión
|
|
CVE-2020-36172
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.8.12 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 5.8.12
|
5.8.12 |
2020-06-10 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12 |
— |
Desconocido
|
< 5.7.12
|
5.7.12 |
2019-02-15 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8 |
— |
Desconocido
|
< 5.7.8
|
5.7.8 |
2018-12-10 |
✓ corregido en la última versión
|
|
CVE-2018-20986
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 5.7.8
|
5.7.8 |
2018-12-07 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 1.1.13 |
— |
Desconocido
|
< 1.1.13
|
1.1.13 |
2016-08-08 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 |
— |
Desconocido
|
< 3.5.2
|
3.5.2 |
2013-01-03 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 |
— |
Desconocido
|
< 3.5.2
|
3.5.2 |
2013-01-03 |
✓ corregido en la última versión
|
|
CVE-2026-4812
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.7.1 |
— |
Media
5,3
|
< 6.7.1
|
6.7.1 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12 |
— |
Desconocido
|
< 5.7.12
|
5.7.12 |
— |
✓ corregido en la última versión
|
|
—
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 |
— |
Desconocido
|
< 3.5.2
|
3.5.2 |
— |
✓ corregido en la última versión
|
CVE-2024-9529
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to limited arbitrary function calls via the 'register_meta_box_cb' and 'meta_box_cb' parameters in all versions up to, and including, 6.3.8 (excluding 6.3.6.2) due to insufficient input validation on those parameters. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary functions, like WordPress functions, in custom post types that will execute whenever a user accesses the injected post type. This can be leveraged to trick other users like administrators accessing posts into performing unauthorized actions through functions, and is not a very serious risk for the vast majority of site owners. Please follow the reference listed in this vulnerability record for instructions on how to update to the latest version of ACF that patches this issue and ensures accessibility to updates moving forward. Please note this issue was partially patched in 6.3.8 and 6.3.6.1 - 6.3.6.2, however, was hardened further in 6.3.6.3 and 6.3.9.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-45429
The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field groups in all versions up to, and including, 6.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with the 'capability' setting privilege, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-4565
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to arbitrary custom field access in all versions up to, and including, 6.2.10. This is due to the plugin not properly restricting what post meta can be displayed through the plugin's shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve potentially sensitive information from custom fields.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-6701
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5
Update the WordPress Advanced Custom Fields plugin to the latest available version (at least 6.2.5).
Francesco Carlucci discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Custom Fields Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.2.5.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-40068
Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8
The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF post type and taxonomy labels in versions 6.1 to 6.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8
Update the WordPress Advanced Custom Fields plugin to the latest available version (at least 6.1.8).
Satoo Nakano, Ryotaro Imamura discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Custom Fields Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.1.8.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-30777
The plugins do not escape the post_status parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6
The Advanced Custom Fields (free & PRO) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_status' parameter in versions 5.8.10 to 5.12.5 and versions 6.0.0 to 6.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5
Update the WordPress Advanced Custom Fields plugin to the latest available version (at least 5.12.5 or 6.1.0).
Unknown discovered and reported this PHP Object Injection vulnerability in WordPress Advanced Custom Fields Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 6.1.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-1196
The Advanced Custom Fields plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.0.7 via deserialization of untrusted input in custom field values. This makes it possible for authenticated attackers, with contributor-level permissions, and above to inject a PHP Object. No POP chain appears to be present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-40696
The Advanced Custom Fields plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 6.0.2. While the ACF shortcode ensures that the ACF data being accessed is valid data that has been entered into ACF fields, it may be possible with certain site configurations, that contributor-level users may extract sensitive user or configuration data.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-2594
The plugin allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.
By default WordPress does not allow uploading of .php files so this vulnerability is not easily wormable, but there are many other file types that can be uploaded that can be then used with another exploit to execute code or used in a phishing attack to get a user to download and execute a resource from a "trusted" site.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2022-23183
The Advanced Custom Fields plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 5.12. This makes it possible for authenticated attackers with editor access, such as Contributors and above, to view information in the database without the appropriate authorization.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-20865
WordPress Plugin "Advanced Custom Fields" provided by Delicious Brains contains multiple missing authorization vulnerabilities listed below. * Missing authorization related to database browsing (CWE-862) - CVE-2021-20865 * Missing authorization related to user list obtaining (CWE-862) - CVE-2021-20866 * Missing authorization related to field group movement (CWE-862) - CVE-2021-20867 Keitaro Yamazaki of Ierae Security, Inc reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
CVE-2021-20866
WordPress Plugin "Advanced Custom Fields" provided by Delicious Brains contains multiple missing authorization vulnerabilities listed below. * Missing authorization related to database browsing (CWE-862) - CVE-2021-20865 * Missing authorization related to user list obtaining (CWE-862) - CVE-2021-20866 * Missing authorization related to field group movement (CWE-862) - CVE-2021-20867 Keitaro Yamazaki of Ierae Security, Inc reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
CVE-2021-20867
WordPress Plugin "Advanced Custom Fields" provided by Delicious Brains contains multiple missing authorization vulnerabilities listed below. * Missing authorization related to database browsing (CWE-862) - CVE-2021-20865 * Missing authorization related to user list obtaining (CWE-862) - CVE-2021-20866 * Missing authorization related to field group movement (CWE-862) - CVE-2021-20867 Keitaro Yamazaki of Ierae Security, Inc reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.10
Arbitrary ACF Data/Field Groups View and Fields Move vulnerability discovered by Keitaro Yamazaki in WordPress Advanced Custom Fields plugin (versions <= 5.9.9).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2020-36172
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12
Advanced Custom Fields before 5.7.12 fails to sanitize user-supplied input before passing it to the unserialize() function. This allows low-level authenticated users to call PHP Objects and possibly achieve remote code execution if a usable gadget is present in a plugin or theme installed on the same site as the vulnerable plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8
Authenticated Cross-Site Scripting (XSS) vulnerability found by Loading Kura Kura in WordPress Advanced Custom Fields plugin (versions <= 5.7.7).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2018-20986
According to the vendor:
"This release contains a fix to a recently reported XSS vunerability [sic]. This report showed it was possible for a logged in author to save unfiltered HTML within a custom field value. This is something that should not be possible without the unfiltered_html capability."
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 1.1.13
Because of this vulnerability, users can inject JavaScript into pages within /wp-admin/.
Upgrade the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2
WordPress Advanced Custom Fields plugin is prone to a remote file inclusion vulnerability. It allows for remote file inclusion and remote code execution via the export.php script.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2
Advanced Custom Fields up to 3.5.1 is vulnerable to Remote Code Execution. The vulnerability allows for remote file inclusion and remote code execution via the export.php script. This exploit only works when the php option allow_url_include is set to On (Default Off).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-4812
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12
Multiple maybe_unserialize calls result with unserialize of user input. Low priviledged users as contributors, but in many cases visitors too
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2
The Advanced Custom Fields WordPress plugin was affected by a Remote File Inclusion security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Mantén Advanced Custom Fields actualizado — 6.8.6 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.