WordPress security by component
Advanced Custom Fields
Plugin description
Advanced Custom Fields adds custom fields and structured content data to WordPress posts, pages, users, media, and other content types.
Advanced Custom Fields (advanced-custom-fields) is a WordPress plugin with 20 published CVE records in this archive. The latest tracked vulnerability was published May 31, 2026; the highest published CVSS base score is 10.
Plugin slug:
advanced-custom-fieldsLatest vulnerability
CVE-2026-8382: Advanced Custom Fields (ACF®): A security weakness
Advanced Custom Fields (ACF®) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.8.1.
| Safe version |
|
||
|---|---|---|---|
| May 31, 2026 |
CVE-2026-8382
Advanced Custom Fields (ACF®): A security weakness
Advanced Custom Fields (ACF®) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.8.1.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 15, 2026 |
CVE-2026-4812
Advanced Custom Fields (ACF®): A security weakness
Advanced Custom Fields (ACF®) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.7.0.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 05, 2025 |
CVE-2012-10025
Advanced Custom Fields: Code execution
Advanced Custom Fields is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE10.0
NVDPending
|
| Nov 15, 2024 |
CVE-2024-9529
Secure Custom Fields: A security weakness
Secure Custom Fields is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.6
NVDPending
|
| Oct 17, 2024 |
CVE-2024-49593
Advanced Custom Fields: Cross-site scripting
Advanced Custom Fields is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 04, 2024 |
CVE-2024-45429
Advanced Custom Fields: Cross-site scripting
Advanced Custom Fields is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jun 20, 2024 |
CVE-2024-4565
Advanced Custom Fields (ACF): A security weakness
Advanced Custom Fields (ACF) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD6.5
|
| Feb 05, 2024 |
CVE-2023-6701
Advanced Custom Fields (ACF): Cross-site scripting
Advanced Custom Fields (ACF) is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 08, 2024 |
CVE-2022-40696
Advanced Custom Fields (ACF): A security weakness
Advanced Custom Fields (ACF) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE3.7
NVD7.5
|
| Aug 21, 2023 |
CVE-2023-40068
Advanced Custom Fields: Cross-site scripting
Advanced Custom Fields is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| May 02, 2023 |
CVE-2023-1196
Advanced Custom Fields: Code execution
Advanced Custom Fields is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Aug 22, 2022 |
CVE-2022-2594
Advanced Custom Fields: A security weakness
Advanced Custom Fields is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Mar 31, 2022 |
CVE-2022-23183
Advanced Custom Fields: A security weakness
Advanced Custom Fields is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Jan 24, 2022 |
CVE-2021-24865
Advanced Custom Fields: Extended: SQL injection
Advanced Custom Fields: Extended is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD7.2
|
| Dec 13, 2021 |
CVE-2021-20867
Advanced Custom Fields: A security weakness
Advanced Custom Fields is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Dec 13, 2021 |
CVE-2021-20866
Advanced Custom Fields: A security weakness
Advanced Custom Fields is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Dec 13, 2021 |
CVE-2021-20865
Advanced Custom Fields: A security weakness
Advanced Custom Fields is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Apr 22, 2021 |
CVE-2021-24241
Advanced Custom Fields Pro: Cross-site scripting
Advanced Custom Fields Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jan 06, 2021 |
CVE-2020-36172
Advanced Custom Fields: Cross-site scripting
Advanced Custom Fields is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Aug 22, 2019 |
CVE-2018-20986
Advanced Custom Fields: Cross-site scripting
Advanced Custom Fields is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|