CVE-2025-13486: Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepareform() function. This is due to the function accepting user input and then passing that through calluserfuncarray(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13486?
CVE-2025-13486 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-13486?
To fix CVE-2025-13486, update the Advanced Custom Fields: Extended plugin to version 0.9.1.2 or later.
Which versions of the Advanced Custom Fields: Extended plugin are affected by CVE-2025-13486?
CVE-2025-13486 affects versions 0.9.0.5 through 0.9.1.1 of the Advanced Custom Fields: Extended plugin.
What kind of attack does CVE-2025-13486 enable?
CVE-2025-13486 enables remote code execution attacks through the improper handling of user inputs.
Who is the vendor associated with CVE-2025-13486?
The vendor associated with CVE-2025-13486 is Advanced Custom Fields.