Incorrectly Configured Access Control Security Levels Expose Advanced Custom Fields PRO to Missing Authorization Vulnerability
CVE-2024-37250
5.4MEDIUM
What is CVE-2024-37250?
Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.
Affected Version(s)
Advanced Custom Fields PRO <= 6.3.1