WordPress security changelog
HIGH CVE-2026-80467 Deferred

ACF Extended front-end registration permits unauthenticated privilege escalation

ACF Extended 0.9.2.2 through 0.9.2.6 does not restrict a front-end registration role to the roles offered by the form, and its privileged-role safeguard is incomplete. An unauthenticated visitor can register with elevated capabilities and then escalate the account to Administrator.

CVE / CNA score 8.1 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
Advanced Custom Fields: Extended
Plugin slug
acf-extended
Affected
0.9.2.2 to < 0.9.2.7
Safe version
0.9.2.7
Published
Sep 02, 2026
Weakness
CWE-269 — Improper Privilege Management

This CVE was published Sep 02, 2026 and is one of 7 known issues for this plugin.

Update, patch or deactivate.

Update to ACF Extended 0.9.2.7 or later, disable affected front-end registration until updated, and audit new accounts and role changes.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.

CVE / CNA vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Primary and upstream sources