CVE-2024-34762
About
Vulnerability discovered by executing a planned security audit.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.
Rainforest analyst review
Advanced Custom Fields PRO can be steered into including a PHP file chosen via a traversal-style path, giving an attacker local file inclusion on the server. ACF is a staple of the WordPress ecosystem, so the potential footprint is large, and LFI on a PHP stack can escalate toward code execution depending on what files can be pulled into the include.
The exploitation reality is tempered by the entry requirement: it needs some authenticated access rather than being wide open, which pulls it out of the pure botnet-bait category that unauthenticated plugin RCE occupies. That said, WordPress sites frequently hand out low-privilege accounts, and the scope change means a successful include reaches beyond the plugin's own boundary, so the low bar of authentication shouldn't be mistaken for a strong wall.
Our job is the familiar plugin-inventory sweep, sharpened by the auth precondition. We map which sites run ACF PRO and at what version, then prioritize those that permit self-registration or have many low-privilege users, since those are where 'authenticated' is cheapest. For sites where accounts are tightly held, this ranks a notch below its 9.9; for open-registration sites, it's close to the full weight of that score.
References
Related CVEs
Frequently asked questions
What is CVE-2024-34762?
Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.
How severe is CVE-2024-34762?
CVE-2024-34762 carries a CVSS 3.1 base score of 9.9, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2024-34762 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.
How do I fix CVE-2024-34762?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
