Advanced Custom Fields (ACF®) <= 6.7.0 - Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters
Advanced Custom Fields (ACF®)
Minimum safe version
6.7.1
Update to 6.7.1 or later to address 35 fixable vulnerabilities
WordPress plugin "Advanced Custom Fields" vulnerable to HTML injection
CVE-2025-54940
WordPress Advanced Custom Fields Plugin <= 3.5.1 is vulnerable to Remote Code Execution (RCE)
CVE-2012-10025
WordPress Advanced Custom Fields Plugin <= 6.3.6.2 is vulnerable to Cross Site Scripting (XSS)
Advanced Custom Fields <= 6.3.8 & Secure Custom Fields <= 6.3.6.2 - Authenticated (Admin+) Stored Cross-Site Scripting
CVE-2024-49593
Advanced Custom Fields <= 6.3.8 - Authenticated (Admin+) Limited Arbitrary Function Call
CVE-2024-9529
CVE-2024-45429
CVE-2024-4565
WordPress Advanced Custom Fields Plugin < 6.2.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-6701
CVE-2023-40068
CVE-2023-30777
WordPress Advanced Custom Fields Plugin <= 6.1.7 is vulnerable to Cross Site Scripting (XSS)
Advanced Custom Fields 6.1 - 6.1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
Advanced Custom Fields (Free and Pro) 5.8.10 to 5.12.5 & 6.0.0 to 6.1.5 - Reflected Cross-Site Scripting via 'post_status'
CVE-2023-1196
WordPress Advanced Custom Fields Plugin <= 6.0.7 is vulnerable to PHP Object Injection
Advanced Custom Fields <= 3.5.1 - Remote Code Execution via Remote File Inclusion
Advanced Custom Fields <= 5.7.11 - PHP Object Injection
CVE-2022-40696
Advanced Custom Fields <= 3.5.1 - Remote File Inclusion
Advanced Custom Fields <= 5.7.10 - Unserialize of user input
CVE-2022-2594
WordPress Advanced Custom Fields Plugin - Remote File Inclusion
WordPress Advanced Custom Fields Plugin <= 1.1.12 - Stored Cross Site Scripting
WordPress Advanced Custom Fields plugin <= 5.7.7 - Authenticated Cross-Site Scripting (XSS) vulnerability
WordPress Advanced Custom Fields plugin <= 5.9.9 - Arbitrary ACF Data/Field Groups View and Fields Move vulnerability
CVE-2022-23183
CVE-2018-20986
CVE-2020-36172
WordPress Advanced Custom Fields Plugin < 5.11 is vulnerable to Broken Access Control
WordPress Advanced Custom Fields Plugin < 5.11 is vulnerable to Broken Access Control
WordPress Advanced Custom Fields Plugin < 5.11 is vulnerable to Broken Access Control