sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total6
Critical3
High0
Medium3
Reset
Showing 1-6 of 6 records
Threat Entry Updated 2026-07-21

Acf Extended - Privilege Escalation (CVE-2026-8809)

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with no authentication or integrity verification — to select a cleanup branch that silently discards all validation errors not prefixed with acfe:. This makes it possible for unauthenticated attackers to suppress both the role allow-list validation error added by acfe_field_user_roles::validate_front_value() and the administrator-role capability guard error added by acfe_module_form_action_user::validate_action(), causing…

PLUGIN Acf Extended

CVE-2026-8809

CRITICAL CVSS 9.8 2026-05-28
Threat Entry Updated 2026-06-17

Acf Extended - Security Vulnerability (CVE-2025-15463)

The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Acf Extended

CVE-2025-15463

MEDIUM CVSS 6.5 2026-05-12
Threat Entry Updated 2026-06-17

Acf Extended - Privilege Escalation (CVE-2025-14533)

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can only be exploited if 'role' is mapped to the custom field.

PLUGIN Acf Extended

CVE-2025-14533

CRITICAL CVSS 9.8 2026-01-20
Threat Entry Updated 2026-06-17

Acf Extended - Remote Code Execution (CVE-2025-13486)

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.

PLUGIN Acf Extended

CVE-2025-13486

CRITICAL CVSS 9.8 2025-12-03
Threat Entry Updated 2026-06-17

Acf Extended - Cross-Site Scripting (XSS) (CVE-2023-5292)

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acfe_form' shortcode in versions up to, and including, 0.8.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Acf Extended

CVE-2023-5292

MEDIUM CVSS 6.4 2023-10-20