Critical Vulnerability in Advanced Custom Fields: Extended Plugin Puts 100,000 WordPress Sites at Risk
ID: c62d2abf-0c6a-5ca2-b6c1-e9848b7b3b97
STIX ID: report--c62d2abf-0c6a-5ca2-b6c1-e9848b7b3b97
Feed Name: The Cyber Express
Threat Score
A critical (9.8) unauthenticated privilege escalation vulnerability in the Advanced Custom Fields: Extended WordPress plugin allows attackers to change a submitted user role (e.g., from subscriber to administrator) via front-end form manipulation, enabling full site takeover for sites running versions up to 0.9.2.1; the issue is patched in 0.9.2.2 and site owners are advised to update or disable the plugin immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
