Advanced Forms for ACF <= 1.9.3.7 - Missing Authorization
medium
The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.3.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.9.3.7
- Fixed in:
- 1.9.3.8
- Disclosed:
- Jul 7, 2026
CVE-2026-57378 on NVD →
Advanced Forms for ACF <= 1.9.3.2 - Missing Authorization to Unauthenticated Form Settings Export
medium
The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_json_file() function in all versions up to, and including, 1.9.3.2. This makes it possible for unauthenticated attackers to export form settings.
- CVSS:
- 5.3
- Affected:
- up to 1.9.3.2
- Fixed in:
- 1.9.3.3
- Disclosed:
- Feb 5, 2024
CVE-2024-1121 on NVD →
Advanced Forms for ACF <= 1.6.8 - Insecure Direct Object Reference
high
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To exploit this vulnerability, an attacker must...
- CVSS:
- 8.8
- Affected:
- up to 1.6.9
- Fixed in:
- 1.6.9
- Disclosed:
- Jun 27, 2020
CVE-2021-24892 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database