PT-2026-44580 · WordPress · Advanced Custom Fields: Extended

·

CVE-2026-8809

·

Published

2026-05-28

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Custom Fields: Extended versions prior to 0.9.2.6
Description This issue allows unauthenticated attackers to achieve privilege escalation through a validation bypass. The after validate save post() function unconditionally trusts the acf post id POST parameter without authentication or integrity verification. This allows an attacker to select a cleanup branch that discards validation errors not prefixed with acfe:, effectively suppressing the role allow-list validation error from acfe field user roles::validate front value() and the administrator-role capability guard error from acfe module form action user::validate action(). Consequently, wp insert user() can be executed with an attacker-supplied administrator role, leading to the creation of a new administrator-level account. Exploitation is possible if the site exposes a public ACFE frontend form configured with a Create User action that maps a role field.
Recommendations Update Advanced Custom Fields: Extended to version 0.9.2.6 or later.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8809

Affected Products

Advanced Custom Fields: Extended