Vulnerability Management, Identity, Privileged access management, Patch/Configuration Management

ACF Extended WordPress plugin flaw poses admin permission compromise risk

(Credit: Bilal Ulker – stock.adobe.com)

Nearly half of the 100,000 WordPress sites with the ACF Extended plugin could still be impacted by the critical vulnerability, tracked as CVE-2025-14533, which could be leveraged to facilitate procurement of administrative permissions, according to BleepingComputer.

Attackers could exploit the flaw, which stems from inadequate role restrictions during form-based user creation or updates and affects ACF Extended versions 0.9.2.1 and earlier, to achieve total site compromise, reported Wordfence. "In the vulnerable version [of the plugin], there are no restrictions for form fields, so the user's role can be set arbitrarily, even to 'administrator', regardless of the field settings, if there is a role field added to the form," Wordfence said.

Such a development comes as widespread WordPress plugin reconnaissance efforts were observed by GreyNoise between late October 2025 and mid-January 2026. Most subjected to enumeration events were the Post SMTP, Loginizer, and LiteSpeed Cache add-ons.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds