Advancedcustomfields
Advancedcustomfields Advanced Custom Fields: vulnerabilities and CVEs
Advancedcustomfields Advanced Custom Fields has 20 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs20
Last 12 months2
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8382 | Medium (5.3) | 0.52% | — | May 31, 2026 | The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to… |
| CVE-2026-4812 | Medium (5.3) | 0.86% | — | Apr 15, 2026 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting… |
| CVE-2025-54940 | Medium (4.6) | 0.21% | — | Aug 8, 2025 | An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered. |
| CVE-2012-10025 | Critical (10) | 1.8% | — | Aug 5, 2025 | The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is… |
| CVE-2024-9529 | Medium (6.6) | 0.43% | — | Nov 15, 2024 | The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary… |
| CVE-2024-49593 | Medium (5.3) | 0.53% | — | Oct 17, 2024 | In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS… |
| CVE-2024-4565 | Medium (6.5) | 0.43% | — | Jun 20, 2024 | The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct… |
| CVE-2023-6701 | Medium (5.4) | 0.52% | — | Feb 5, 2024 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output… |
| CVE-2022-40696 | High (7.5) | 0.52% | — | Jan 8, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2. |
| CVE-2023-40068 | Medium (5.4) | 2.0% | — | Aug 21, 2023 | Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the… |
| CVE-2023-30777 | Medium (6.1) | 39% | — | May 10, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions. |
| CVE-2023-1196 | High (8.8) | 1.1% | — | May 2, 2023 | The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP… |
| CVE-2022-2594 | High (8.8) | 1.6% | — | Aug 22, 2022 | The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not… |
| CVE-2022-23183 | Medium (6.5) | 1.5% | — | Mar 31, 2022 | Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the… |
| CVE-2021-20867 | Medium (6.5) | 1.4% | — | Dec 13, 2021 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized… |
| CVE-2021-20866 | Medium (6.5) | 1.7% | — | Dec 13, 2021 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the… |
| CVE-2021-20865 | High (7.5) | 2.5% | — | Dec 13, 2021 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data… |
| CVE-2021-24241 | Medium (6.1) | 1.4% | — | Apr 22, 2021 | The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings… |
| CVE-2020-36172 | Medium (6.1) | 0.90% | — | Jan 6, 2021 | The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS. |
| CVE-2018-20986 | Medium (5.4) | 0.95% | — | Aug 22, 2019 | The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.