PT-2026-44580 · WordPress · Advanced Custom Fields: Extended
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advanced Custom Fields: Extended versions prior to 0.9.2.6
Description
This issue allows unauthenticated attackers to achieve privilege escalation through a validation bypass. The
after validate save post() function unconditionally trusts the acf post id POST parameter without authentication or integrity verification. This allows an attacker to select a cleanup branch that discards validation errors not prefixed with acfe:, effectively suppressing the role allow-list validation error from acfe field user roles::validate front value() and the administrator-role capability guard error from acfe module form action user::validate action(). Consequently, wp insert user() can be executed with an attacker-supplied administrator role, leading to the creation of a new administrator-level account. Exploitation is possible if the site exposes a public ACFE frontend form configured with a Create User action that maps a role field.Recommendations
Update Advanced Custom Fields: Extended to version 0.9.2.6 or later.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Custom Fields: Extended