Critical Flaw in “Advanced Custom Fields: Extended” Exposes 100K WordPress Sites to Takeover
ID: 0430a3b5-703d-522a-a34c-25c4d2c4b05a
STIX ID: report--0430a3b5-703d-522a-a34c-25c4d2c4b05a
Feed Name: securityonline.info
Threat Score
A critical privilege-escalation vulnerability (CVE-2025-14533, CVSS 9.8) was discovered in the Advanced Custom Fields: Extended WordPress plugin that allows unauthenticated attackers to set arbitrary user roles via certain user-creation/update forms—potentially granting full administrative control; a patch was released in version 0.9.2.2 and site owners are urged to update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
