logo

Critical WordPress Plugin Vulnerability Exposes 100,000+ Websites to Privilege Escalation Attacks

ID: 70feb513-035c-578d-9ad4-116418f61f36

STIX ID: report--70feb513-035c-578d-9ad4-116418f61f36

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A critical privilege-escalation vulnerability (CVE-2025-14533, CVSS 9.8) in the Advanced Custom Fields:Extended WordPress plugin allows unauthenticated attackers to assign themselves the administrator role via the plugin's insert_user form action. The flaw affects versions ≤0.9.2.1 (over 100,000 active installations) and has been fixed in 0.9.2.2; administrators are urged to update immediately and apply available mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.