PT-2025-47263 · WordPress · Acf Flexible Layouts Manager

Ahmad Salem

·

Published

2025-11-18

·

Updated

2025-11-18

·

CVE-2025-12937

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ACF Flexible Layouts Manager plugin for WordPress versions up to and including 1.1.6
Description The ACF Flexible Layouts Manager plugin for WordPress has a flaw that allows unauthorized modification of data. This is due to a missing capability check within the acf flm update template with pasted layout() function. This allows unauthenticated attackers to update custom field values on individual posts and pages.
Recommendations Update the ACF Flexible Layouts Manager plugin to a version later than 1.1.6.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12937

Affected Products

Acf Flexible Layouts Manager