Extension WordPress
Vulnérabilités Advanced Custom Fields (ACF®)
Cette page rassemble les failles publiées pour Advanced Custom Fields (ACF®), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Advanced Custom Fields (ACF®)
22 fiches
Advanced Custom Fields (ACF®) <= 6.8.1 – Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an…
*-6.8.1
6.8.2
30/05/2026
Advanced Custom Fields (ACF®) <= 6.8.1 – Missing Authorization
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.8.1. This makes it possible for unauthenticated attackers to perform…
*-6.8.1
6.8.2
27/05/2026
Advanced Custom Fields (ACF®) <= 6.7.0 – Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override…
*-6.7.0
6.7.1
14/04/2026
Advanced Custom Fields <= 6.4.2. – HTML Injection
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 6.4.2. This is due to the plugin nor properly neutralizing unsafe HTML. This makes it possible for authenticated…
*-6.4.2
6.4.3
08/08/2025
Advanced Custom Fields <= 6.3.8 & Secure Custom Fields <= 6.3.6.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The Advanced Custom Fields & Secure Custom Fields plugins for WordPress are vulnerable to Stored Cross-Site Scripting via ACF field labels in all versions up to, and including, 6.3.8 & 6.3.6.2 respectively due to insufficient input sanitization and…
*-6.3.6, *-6.3.6.2, 6.3.7, 6.3.8
6.3.9
15/10/2024
Advanced Custom Fields <= 6.3.8 – Authenticated (Admin+) Limited Arbitrary Function Call
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to limited arbitrary function calls via the 'register_meta_box_cb' and 'meta_box_cb' parameters in all versions up to, and including, 6.3.8 (excluding 6.3.6.2) due to insufficient input validation on those…
*-6.3.6, *-6.3.6.2, 6.3.7, 6.3.8
6.3.9
07/10/2024
Advanced Custom Fields <= 6.3.5 – Authenticated Stored Cross-Site Scripting
The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field groups in all versions up to, and including, 6.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-6.3.5
6.3.6
04/09/2024
Advanced Custom Fields <= 6.2.10 – Authenticated (Contributor+) Arbitrary Custom Field Access
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to arbitrary custom field access in all versions up to, and including, 6.2.10. This is due to the plugin not properly restricting what post meta can be displayed…
*-6.2.10
6.3.0
30/05/2024
Advanced Custom Fields <= 6.2.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it…
*-6.2.4
6.2.5
17/01/2024
Advanced Custom Fields 6.1 – 6.1.7 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF post type and taxonomy labels in versions 6.1 to 6.1.7 due to insufficient input sanitization and output escaping. This makes it possible for…
6.1-6.1.7
6.1.8
03/08/2023
Advanced Custom Fields (Free and Pro) 5.8.10 to 5.12.5 & 6.0.0 to 6.1.5 – Reflected Cross-Site Scripting via 'post_status'
The Advanced Custom Fields (free & PRO) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_status' parameter in versions 5.8.10 to 5.12.5 and versions 6.0.0 to 6.1.5 due to insufficient input sanitization and output escaping.…
5.8.10-5.12.5, 6.0.0-6.1.5
5.12.6, 6.1.6
04/05/2023
Advanced Custom Fields <= 6.0.7 – Authenticated (Contributor+) PHP Object Injection
The Advanced Custom Fields plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.0.7 via deserialization of untrusted input in custom field values. This makes it possible for authenticated attackers, with contributor-level…
*-5.12.4, 6.0.0-6.0.7
5.12.5, 6.1.0
03/04/2023
Advanced Custom Fields <= 6.0.2 – Authenticated (Contributor+) Information Disclosure
The Advanced Custom Fields plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 6.0.2. While the ACF shortcode ensures that the ACF data being accessed is valid data that has been entered…
*-6.0.2
6.0.3
18/10/2022
Advanced Custom Fields <= 5.12.2 – File Upload
The Advanced Custom Fields plugin for WordPress has a file upload vulnerability in versions up to, and including, 5.12.2. This allows users without the upload_files capability, such as contributors, or unauthenticated users in cases where a frontend form…
*-5.12.2
5.12.3
14/07/2022
Advanced Custom Fields <= 5.12 – Authenticated Information Disclosure
The Advanced Custom Fields plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 5.12. This makes it possible for authenticated attackers with editor access, such as Contributors…
[*, 5.12.1)
5.12.1
30/03/2022
Advanced Custom Fields <= 5.10 – Missing Authorization to Information Disclosure
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified…
[*, 5.11)
5.11
02/12/2021
Advanced Custom Fields <= 5.10 – Missing Authorization to Information Disclosure
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.
[*, 5.11)
5.11
02/12/2021
Advanced Custom Fields <= 5.10 – Missing Authorization on Option Changes
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via…
[*, 5.11)
5.11
02/12/2021
Advanced Custom Fields <= 5.8.11 – Cross-Site Scripting
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
[*, 5.8.12)
5.8.12
10/06/2020
Advanced Custom Fields <= 5.7.11 – PHP Object Injection
Advanced Custom Fields before 5.7.12 fails to sanitize user-supplied input before passing it to the unserialize() function. This allows low-level authenticated users to call PHP Objects and possibly achieve remote code execution if a usable gadget is present…
*-5.7.11
5.7.12
15/02/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.