PT-2026-45169 · WordPress · Advanced Custom Fields Pro
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Advanced Custom Fields versions prior to 6.8.2
Description
The Advanced Custom Fields plugin for WordPress contains an authorization bypass issue because it fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can overwrite the
post title and post content of any post linked to a publicly accessible acf form() instance. This is achieved by injecting values into the post title and post content parameters during a form submission request.Recommendations
Update to version 6.8.2 or later.
As a temporary mitigation, restrict public access to
acf form() instances.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Custom Fields Pro