CVE-2026-4812: Advanced Custom Fields (ACF®) <= 6.7.0 - Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters

Published Apr 15, 2026
·
Updated

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.

Affected Software

1 affected component
Advanced Custom Fields Advanced Custom Fields<=6.7.0

Event History

Apr 15, 2026
CVE Published
via MITRE·01:25 AM
Data Sourced
via MITRE·01:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-4812?

CVE-2026-4812 has a medium severity rating due to its potential for unauthorized access to posts and pages.

2

How do I fix CVE-2026-4812?

To fix CVE-2026-4812, update the Advanced Custom Fields plugin to a version later than 6.7.0.

3

What specific issue does CVE-2026-4812 address?

CVE-2026-4812 addresses a vulnerability in the Advanced Custom Fields plugin that allows unauthenticated users to access arbitrary post and page content.

4

Which versions are affected by CVE-2026-4812?

CVE-2026-4812 affects versions of Advanced Custom Fields up to and including 6.7.0.

5

Is there a workaround for CVE-2026-4812?

A potential workaround for CVE-2026-4812 includes restricting access to the plugin’s functionality via user permissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203