plugin

Advanced Custom Fields Vulnerabilities

58 known security issues reported for the Advanced Custom Fields WordPress plugin. Most recent disclosed May 30, 2026.

2 high 19 medium 1 low

Running Advanced Custom Fields on your site? Check whether your installed version is affected.

Scan your site free

Advanced Custom Fields (ACF®) <= 6.8.1 - Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters

medium

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and...

CVSS:
5.3
Affected:
up to 6.8.1
Fixed in:
6.8.2
Disclosed:
May 30, 2026

CVE-2026-8382 on NVD →

Advanced Custom Fields (ACF®) <= 6.8.1 - Missing Authorization

medium

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.8.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 6.8.1
Fixed in:
6.8.2
Disclosed:
May 27, 2026

Advanced Custom Fields (ACF®) <= 6.7.0 - Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters

medium

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorizati...

CVSS:
5.3
Affected:
up to 6.7.0
Fixed in:
6.7.1
Disclosed:
Apr 14, 2026

CVE-2026-4812 on NVD →

Advanced Custom Fields <= 6.4.2. - HTML Injection

medium

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 6.4.2. This is due to the plugin nor properly neutralizing unsafe HTML. This makes it possible for authenticated attackers, with administrator-level access and above, to inject potentially malici...

CVSS:
4.1
Affected:
up to 6.4.2
Fixed in:
6.4.3
Disclosed:
Aug 8, 2025

CVE-2025-54940 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3

unknown

Advanced Custom Fields provided by WPEngine, Inc. contains the following vulnerability. <ul><li>HTML injection (WE-94) - CVE-2025-54940</li></ul> Shogo Kumamaru of LAC Co., Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. Solution:...

Affected:
up to 6.4.3
Fixed in:
6.4.3
Disclosed:
Aug 8, 2025

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3

unknown

[en] An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.

Affected:
up to 6.4.3
Fixed in:
6.4.3
Disclosed:
Aug 8, 2025

CVE-2025-54940 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2

unknown

<p>WordPress Advanced Custom Fields Plugin <= 3.5.1 is vulnerable to Remote Code Execution (RCE)</p><p>Software: Advanced Custom Fields</p><p>Fixed in version 3.5.2 </p><p>Affected Version <= 3.5.1</p>

Affected:
up to 3.5.2
Fixed in:
3.5.2
Disclosed:
Aug 5, 2025

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2

unknown

[en] The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to incl...

Affected:
up to 3.5.2
Fixed in:
3.5.2
Disclosed:
Aug 5, 2025

CVE-2012-10025 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8

unknown

[en] The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as a...

Affected:
up to 6.3.8
Fixed in:
6.3.8
Disclosed:
Nov 15, 2024

CVE-2024-9529 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9

unknown

[en] In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of...

Affected:
up to 6.3.9
Fixed in:
6.3.9
Disclosed:
Oct 17, 2024

CVE-2024-49593 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9

unknown

<p>WordPress Advanced Custom Fields Plugin <= 6.3.6.2 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Advanced Custom Fields</p><p>Link: https://wordpress.org/plugins/advanced-custom-fields/#developers</p><p>Affected Version <= 6.3.6.2</p><p>Fixed in version 6.3.6.3 </p>

Affected:
up to 6.3.9
Fixed in:
6.3.9
Disclosed:
Oct 16, 2024

Advanced Custom Fields <= 6.3.8 & Secure Custom Fields <= 6.3.6.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Advanced Custom Fields & Secure Custom Fields plugins for WordPress are vulnerable to Stored Cross-Site Scripting via ACF field labels in all versions up to, and including, 6.3.8 & 6.3.6.2 respectively due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

CVSS:
4.4
Affected:
up to 6.3.6, 6.3.7 – 6.3.7, 6.3.8 – 6.3.8
Fixed in:
6.3.9
Disclosed:
Oct 15, 2024

CVE-2024-49593 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9

unknown

The Advanced Custom Fields & Secure Custom Fields plugins for WordPress are vulnerable to Stored Cross-Site Scripting via ACF field labels in all versions up to, and including, 6.3.8 & 6.3.6.2 respectively due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Affected:
up to 6.3.9
Fixed in:
6.3.9
Disclosed:
Oct 15, 2024

Advanced Custom Fields <= 6.3.8 - Authenticated (Admin+) Limited Arbitrary Function Call

medium

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to limited arbitrary function calls via the 'register_meta_box_cb' and 'meta_box_cb' parameters in all versions up to, and including, 6.3.8 (excluding 6.3.6.2) due to insufficient input validation on those parameters. This makes it possible for authent...

CVSS:
5.1
Affected:
up to 6.3.6, 6.3.7 – 6.3.7, 6.3.8 – 6.3.8
Fixed in:
6.3.9
Disclosed:
Oct 7, 2024

CVE-2024-9529 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8

unknown

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to limited arbitrary function calls via the 'register_meta_box_cb' and 'meta_box_cb' parameters in all versions up to, and including, 6.3.8 (excluding 6.3.6.2) due to insufficient input validation on those parameters. This makes it possible for authent...

Affected:
up to 6.3.8
Fixed in:
6.3.8
Disclosed:
Oct 7, 2024

Advanced Custom Fields <= 6.3.5 - Authenticated Stored Cross-Site Scripting

medium

The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field groups in all versions up to, and including, 6.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with the 'capability' setting privilege, to inject arb...

CVSS:
5.5
Affected:
up to 6.3.5
Fixed in:
6.3.6
Disclosed:
Sep 4, 2024

CVE-2024-45429 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.6

unknown

[en] Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be exec...

Affected:
up to 6.3.6
Fixed in:
6.3.6
Disclosed:
Sep 4, 2024

CVE-2024-45429 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.0

unknown

[en] The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access

Affected:
up to 6.3.0
Fixed in:
6.3.0
Disclosed:
Jun 20, 2024

CVE-2024-4565 on NVD →

Advanced Custom Fields <= 6.2.10 - Authenticated (Contributor+) Arbitrary Custom Field Access

medium

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to arbitrary custom field access in all versions up to, and including, 6.2.10. This is due to the plugin not properly restricting what post meta can be displayed through the plugin's shortcode. This makes it possible for authenticated attackers, with C...

CVSS:
4.3
Affected:
up to 6.2.10
Fixed in:
6.3.0
Disclosed:
May 30, 2024

CVE-2024-4565 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5

unknown

[en] The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and ab...

Affected:
up to 6.2.5
Fixed in:
6.2.5
Disclosed:
Feb 5, 2024

CVE-2023-6701 on NVD →

Advanced Custom Fields <= 6.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field

medium

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...

CVSS:
6.4
Affected:
up to 6.2.4
Fixed in:
6.2.5
Disclosed:
Jan 17, 2024

CVE-2023-6701 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5

unknown

Update the WordPress Advanced Custom Fields plugin to the latest available version (at least 6.2.5). Francesco Carlucci discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Custom Fields Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, adv...

Affected:
up to 6.2.5
Fixed in:
6.2.5
Disclosed:
Jan 16, 2024

Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 3.1.1 - <= 6.0.2

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2.

Affected:
3.1.1 – 6.0.2
Fixed in:
6.0.2
Disclosed:
Jan 8, 2024

CVE-2022-40696 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 6.1.0 - <= 6.1.7

unknown

[en] Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.

Affected:
6.1.0 – 6.1.7
Fixed in:
6.1.7
Disclosed:
Aug 21, 2023

CVE-2023-40068 on NVD →

Advanced Custom Fields 6.1 - 6.1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF post type and taxonomy labels in versions 6.1 to 6.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

CVSS:
4.4
Affected:
6.1 – 6.1.7
Fixed in:
6.1.8
Disclosed:
Aug 3, 2023

CVE-2023-40068 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8

unknown

Update the WordPress Advanced Custom Fields plugin to the latest available version (at least 6.1.8). Satoo Nakano, Ryotaro Imamura discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Custom Fields Plugin. This could allow a malicious actor to inject malicious scripts, such as re...

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Aug 3, 2023

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8

unknown

The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF post type and taxonomy labels in versions 6.1 to 6.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Aug 3, 2023

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.

Affected:
up to 6.1.6
Fixed in:
6.1.6
Disclosed:
May 10, 2023

CVE-2023-30777 on NVD →

Advanced Custom Fields (Free and Pro) 5.8.10 to 5.12.5 & 6.0.0 to 6.1.5 - Reflected Cross-Site Scripting via 'post_status'

medium

The Advanced Custom Fields (free & PRO) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_status' parameter in versions 5.8.10 to 5.12.5 and versions 6.0.0 to 6.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

CVSS:
6.1
Affected:
5.8.10 – 5.12.5, 6.0.0 – 6.1.5
Fixed in:
5.12.6
Disclosed:
May 4, 2023

CVE-2023-30777 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6

unknown

The Advanced Custom Fields (free & PRO) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_status' parameter in versions 5.8.10 to 5.12.5 and versions 6.0.0 to 6.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

Affected:
up to 6.1.6
Fixed in:
6.1.6
Disclosed:
May 4, 2023

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5

unknown

[en] The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present.

Affected:
up to 5.12.5
Fixed in:
5.12.5
Disclosed:
May 2, 2023

CVE-2023-1196 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5

unknown

Update the WordPress Advanced Custom Fields plugin to the latest available version (at least 5.12.5 or 6.1.0). Unknown discovered and reported this PHP Object Injection vulnerability in WordPress Advanced Custom Fields Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal,...

Affected:
up to 5.12.5
Fixed in:
5.12.5
Disclosed:
Apr 4, 2023

Advanced Custom Fields <= 6.0.7 - Authenticated (Contributor+) PHP Object Injection

high

The Advanced Custom Fields plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.0.7 via deserialization of untrusted input in custom field values. This makes it possible for authenticated attackers, with contributor-level permissions, and above to inject a PHP Object. No POP ch...

CVSS:
8.8
Affected:
up to 5.12.4, 6.0.0 – 6.0.7
Fixed in:
5.12.5
Disclosed:
Apr 3, 2023

CVE-2023-1196 on NVD →

Advanced Custom Fields <= 6.0.2 - Authenticated (Contributor+) Information Disclosure

medium

The Advanced Custom Fields plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 6.0.2. While the ACF shortcode ensures that the ACF data being accessed is valid data that has been entered into ACF fields, it may be possible with certain site configurations, that contributor-le...

CVSS:
4.3
Affected:
up to 6.0.2
Fixed in:
6.0.3
Disclosed:
Oct 18, 2022

CVE-2022-40696 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.3

unknown

[en] The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrit...

Affected:
up to 5.12.3
Fixed in:
5.12.3
Disclosed:
Aug 22, 2022

CVE-2022-2594 on NVD →

Advanced Custom Fields <= 5.12.2 - File Upload

medium

The Advanced Custom Fields plugin for WordPress has a file upload vulnerability in versions up to, and including, 5.12.2. This allows users without the upload_files capability, such as contributors, or unauthenticated users in cases where a frontend form is added to the site, to upload allowed file types. The upload is...

CVSS:
4.3
Affected:
up to 5.12.2
Fixed in:
5.12.3
Disclosed:
Jul 14, 2022

CVE-2022-2594 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1

unknown

[en] Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permission.

Affected:
up to 5.12.1
Fixed in:
5.12.1
Disclosed:
Mar 31, 2022

CVE-2022-23183 on NVD →

Advanced Custom Fields <= 5.12 - Authenticated Information Disclosure

medium

The Advanced Custom Fields plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 5.12. This makes it possible for authenticated attackers with editor access, such as Contributors and above, to view information in the database without the appropria...

CVSS:
6.5
Affected:
up to 5.12.1
Fixed in:
5.12.1
Disclosed:
Mar 30, 2022

CVE-2022-23183 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1

unknown

[en] Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.

Affected:
up to 5.12.1
Fixed in:
5.12.1
Disclosed:
Dec 13, 2021

CVE-2021-20867 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11

unknown

[en] Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.

Affected:
up to 5.11
Fixed in:
5.11
Disclosed:
Dec 13, 2021

CVE-2021-20866 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11

unknown

[en] Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.

Affected:
up to 5.11
Fixed in:
5.11
Disclosed:
Dec 13, 2021

CVE-2021-20865 on NVD →

Advanced Custom Fields <= 5.10 - Missing Authorization to Information Disclosure

high

Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.

CVSS:
7.5
Affected:
up to 5.11
Fixed in:
5.11
Disclosed:
Dec 2, 2021

CVE-2021-20865 on NVD →

Advanced Custom Fields <= 5.10 - Missing Authorization to Information Disclosure

medium

Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.

CVSS:
6.5
Affected:
up to 5.11
Fixed in:
5.11
Disclosed:
Dec 2, 2021

CVE-2021-20866 on NVD →

Advanced Custom Fields <= 5.10 - Missing Authorization on Option Changes

medium

Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.

CVSS:
4.3
Affected:
up to 5.11
Fixed in:
5.11
Disclosed:
Dec 2, 2021

CVE-2021-20867 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.10

unknown

Arbitrary ACF Data/Field Groups View and Fields Move vulnerability discovered by Keitaro Yamazaki in WordPress Advanced Custom Fields plugin (versions <= 5.9.9).

Affected:
up to 5.10
Fixed in:
5.10
Disclosed:
Aug 25, 2021

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.8.12

unknown

[en] The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.

Affected:
up to 5.8.12
Fixed in:
5.8.12
Disclosed:
Jan 6, 2021

CVE-2020-36172 on NVD →

Advanced Custom Fields <= 5.8.11 - Cross-Site Scripting

medium

The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.

CVSS:
6.1
Affected:
up to 5.8.12
Fixed in:
5.8.12
Disclosed:
Jun 10, 2020

CVE-2020-36172 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8

unknown

[en] The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.

Affected:
up to 5.7.8
Fixed in:
5.7.8
Disclosed:
Aug 22, 2019

CVE-2018-20986 on NVD →

Advanced Custom Fields <= 5.7.11 - PHP Object Injection

medium

Advanced Custom Fields before 5.7.12 fails to sanitize user-supplied input before passing it to the unserialize() function. This allows low-level authenticated users to call PHP Objects and possibly achieve remote code execution if a usable gadget is present in a plugin or theme installed on the same site as the vulner...

CVSS:
5.4
Affected:
up to 5.7.11
Fixed in:
5.7.12
Disclosed:
Feb 15, 2019

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12

unknown

Advanced Custom Fields before 5.7.12 fails to sanitize user-supplied input before passing it to the unserialize() function. This allows low-level authenticated users to call PHP Objects and possibly achieve remote code execution if a usable gadget is present in a plugin or theme installed on the same site as the vulner...

Affected:
up to 5.7.12
Fixed in:
5.7.12
Disclosed:
Feb 15, 2019

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by Loading Kura Kura in WordPress Advanced Custom Fields plugin (versions <= 5.7.7).

Affected:
up to 5.7.8
Fixed in:
5.7.8
Disclosed:
Dec 10, 2018

Advanced Custom Fields <= 5.7.7 - Author+ Stored Cross-Site Scripting

medium

The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.

CVSS:
5.4
Affected:
up to 5.7.8
Fixed in:
5.7.8
Disclosed:
Dec 7, 2018

CVE-2018-20986 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 1.1.13

unknown

Because of this vulnerability, users can inject JavaScript into pages within /wp-admin/. Upgrade the plugin.

Affected:
up to 1.1.13
Fixed in:
1.1.13
Disclosed:
Aug 8, 2016

Advanced Custom Fields <= 3.5.1 - Remote Code Execution via Remote File Inclusion

low

Advanced Custom Fields up to 3.5.1 is vulnerable to Remote Code Execution. The vulnerability allows for remote file inclusion and remote code execution via the export.php script. This exploit only works when the php option allow_url_include is set to On (Default Off).

CVSS:
3.8
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Jan 3, 2013

CVE-2012-10025 on NVD →

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2

unknown

WordPress Advanced Custom Fields plugin is prone to a remote file inclusion vulnerability. It allows for remote file inclusion and remote code execution via the export.php script. Update the plugin.

Affected:
up to 3.5.2
Fixed in:
3.5.2
Disclosed:
Jan 3, 2013

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2

unknown

Advanced Custom Fields up to 3.5.1 is vulnerable to Remote Code Execution. The vulnerability allows for remote file inclusion and remote code execution via the export.php script. This exploit only works when the php option allow_url_include is set to On (Default Off).

Affected:
up to 3.5.2
Fixed in:
3.5.2
Disclosed:
Jan 3, 2013

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12

unknown

Multiple maybe_unserialize calls result with unserialize of user input. Low priviledged users as contributors, but in many cases visitors too

Affected:
up to 5.7.12
Fixed in:
5.7.12

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2

unknown

The Advanced Custom Fields WordPress plugin was affected by a Remote File Inclusion security vulnerability.

Affected:
up to 3.5.2
Fixed in:
3.5.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database