Nearly half of the 100,000 WordPress sites with the ACF Extended plugin could still be impacted by the critical vulnerability, tracked as CVE-2025-14533, which could be leveraged to facilitate procurement of administrative permissions, according to BleepingComputer.Attackers could exploit the flaw, which stems from inadequate role restrictions during form-based user creation or updates and affects ACF Extended versions 0.9.2.1 and earlier, to achieve total site compromise, reported Wordfence. "In the vulnerable version [of the plugin], there are no restrictions for form fields, so the user's role can be set arbitrarily, even to 'administrator', regardless of the field settings, if there is a role field added to the form," Wordfence said.Such a development comes as widespread WordPress plugin reconnaissance efforts were observed by GreyNoise between late October 2025 and mid-January 2026. Most subjected to enumeration events were the Post SMTP, Loginizer, and LiteSpeed Cache add-ons.
Vulnerability Management, Identity, Privileged access management, Patch/Configuration Management

ACF Extended WordPress plugin flaw poses admin permission compromise risk

(Credit: Bilal Ulker – stock.adobe.com)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



