CVE-2024-49593
Published
CVSS v3
5.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF, then you can follow the process shown at the advancedcustomfields.com blog URL within the References section below.
<p>Advanced Custom Fields (ACF®) turns WordPress sites into a fully-fledged content management system by giving you all the tools to do more with your data.</p>
<p>Use the ACF plugin to take full control of your WordPress edit screens, custom field data, and more.</p>
<p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/9C6_roqghZQ?version=3&rel=0&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p>
<p><strong>Add fields on demand.</strong><br />
The ACF field builder allows you to quickly and easily add fields to WP edit screens with only the click of a few buttons! Whether it’s something simple like adding an “author” field to a book review post, or something more complex like the structured data needs of an ecommerce site or marketplace, ACF makes adding fields to your content model easy.</p>
<p><strong>Add them anywhere.</strong><br />
Fields can be added all over WordPress including posts, pages, users, taxonomy terms, media, comments and even custom options pages! It couldn’t be simpler to bring structure to the WordPress content creation experience.</p>
<p><strong>Show them everywhere.</strong><br />
Load and display your custom field values in any theme template file with our hassle-free, developer friendly functions! Whether you need to display a single value or generate content based on a more complex query, the out-of-the-box functions of ACF make templating a dream for developers of all levels of experience.</p>
<p><strong>Any Content, Fast.</strong><br />
Turning WordPress into a true content management system is not just about custom fields. Creating new custom post types and taxonomies is an essential part of building custom WordPress sites. Registering post types and taxonomies is now possible right in the ACF UI, speeding up the content modeling workflow without the need to touch code or use another plugin.</p>
<p><strong>Simply beautiful and intentionally accessible.</strong><br />
For content creators and those tasked with data entry, the field user experience is as intuitive as they could desire while fitting neatly into the native WordPress experience. Accessibility standards are regularly reviewed and applied, ensuring ACF is able to empower as close to anyone as possible.</p>
<p><strong>Documentation and developer guides.</strong><br />
Over 10 plus years of vibrant community contribution alongside an ongoing commitment to clear documentation means that you’ll be able to find the guidance you need to build what you want.</p>
<h4>Features</h4>
<ul>
<li>Simple & Intuitive</li>
<li>Powerful Functions</li>
<li>Over 30 Field Types</li>
<li>Extensive Documentation</li>
<li>Millions of Users</li>
</ul>
<h4>Links</h4>
<ul>
<li><a href="https://www.advancedcustomfields.com/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Website" rel="nofollow ugc">Website</a></li>
<li><a href="https://www.advancedcustomfields.com/resources/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Website" rel="nofollow ugc">Documentation</a></li>
<li><a href="https://support.advancedcustomfields.com" rel="nofollow ugc">Support</a></li>
<li><a href="https://www.advancedcustomfields.com/pro/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Pro%20Upgrade" rel="nofollow ugc">ACF PRO</a></li>
</ul>
<h4>PRO</h4>
<p>The Advanced Custom Fields plugin is also available in a professional version which includes more fields, more functionality, and more flexibility. The ACF PRO plugin features:</p>
<ul>
<li>The <a href="https://www.advancedcustomfields.com/resources/repeater/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Pro%20Upgrade" rel="nofollow ugc">Repeater Field</a> allows you to create a set of sub fields which can be repeated again, and again, and again.</li>
<li><a href="https://www.advancedcustomfields.com/resources/blocks/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Pro%20Upgrade" rel="nofollow ugc">ACF Blocks</a>, a powerful PHP-based framework for developing custom block types for the WordPress Block Editor (aka Gutenberg).</li>
<li>Define, create, and manage content with the <a href="https://www.advancedcustomfields.com/resources/flexible-content/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Pro%20Upgrade" rel="nofollow ugc">Flexible Content Field</a>, which provides for multiple layout and sub field options.</li>
<li>Use the <a href="https://www.advancedcustomfields.com/resources/options-page/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Pro%20Upgrade" rel="nofollow ugc">Options Page</a> feature to add custom admin pages to edit ACF fields.</li>
<li>Build fully customisable image galleries with the <a href="https://www.advancedcustomfields.com/resources/gallery/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Pro%20Upgrade" rel="nofollow ugc">Gallery Field</a>.</li>
<li>Unlock a more efficient workflow for managing field settings by reusing existing fields and field groups on demand with the <a href="https://www.advancedcustomfields.com/resources/clone/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Pro%20Upgrade" rel="nofollow ugc">Clone Field</a>.</li>
</ul>
<p><a href="https://www.advancedcustomfields.com/pro/?utm_source=wordpress.org&utm_medium=free%20plugin%20listing&utm_campaign=ACF%20Pro%20Upgrade" rel="nofollow ugc">Upgrade to ACF PRO</a></p>