← WordPress Vulnerabilities
WordPress security by component

Advanced Custom Fields: Extended

Advanced Custom Fields: Extended is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Dec 03, 2025; the highest published CVSS base score is 9.8.

Plugin slug: advanced-custom-fields-extended

CVE-2025-13486: Advanced Custom Fields: Extended: Code execution

Advanced Custom Fields: Extended is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedDec 03, 2025
Safe version guidanceSee mitigation notes
Published vulnerabilities for advanced-custom-fields-extended
Safe version
Dec 03, 2025 CVE-2025-13486
Advanced Custom Fields: Extended: Code execution
Advanced Custom Fields: Extended is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE9.8
NVDPending