ACF plugin bug gives hackers admin on 50,000 WordPress sites
ID: 8e4fe58b-a42e-5976-b536-b455863d5499
STIX ID: report--8e4fe58b-a42e-5976-b536-b455863d5499
Feed Name: Bleeping Computer
Threat Score
A critical privilege-escalation flaw (CVE-2025-14533) in the ACF Extended WordPress plugin allowed unauthenticated attackers to set user roles arbitrarily via the ‘Insert User/Update User’ form, potentially granting administrator access to many sites; the vendor released a fix in v0.9.2.2, but approximately 50,000 sites may remain exposed. The report also highlights widespread WordPress plugin enumeration activity and notes active exploitation of other plugin vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
