ACF plugin bug gives hackers admin on 50,000 WordPress sites

ACF plugin bug gives hackers admin on 50,000 WordPress sites

A serious vulnerability in the ACF Extended WordPress plugin allows attackers to gain admin access without authentication. This flaw has affected numerous websites and highlights the importance of timely plugin updates. #CVE-2025-14533 #WordPressSecurity

Keypoints

  • A critical security flaw in the ACF Extended plugin enables remote privilege escalation.
  • Over 100,000 websites use the vulnerable ACF Extended plugin, increasing attack exposure.
  • The vulnerability involves the β€˜Insert User / Update User’ form, which lacks role restrictions.
  • Exploitation can lead to full site compromise, especially if a role field is used in user forms.
  • Although no attacks have been observed yet, large-scale reconnaissance activity has been detected.

Read More: https://www.bleepingcomputer.com/news/security/acf-plugin-bug-gives-hackers-admin-on-50-000-wordpress-sites/