CVE-2026-81284: WordPress ACF Extended plugin <= 0.9.2.6 - Broken Access Control vulnerability
Published Aug 28, 2026
·Updated
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Affected Software
1 affected component
WordPress ACF Extended plugin<=0.9.2.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/acf-extendedto a version that resolves this vulnerability.Fixed in 0.9.2.7
Event History
Aug 28, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
Exploitation requires an authenticated account with Contributor-level access. It is not indicated as exploitable by an unauthenticated visitor.
2
What is the expected impact if exploited?
The rating indicates a low integrity impact, with no confidentiality or availability impact. The vulnerability could allow unauthorized modification-related actions within the affected access-control boundary.
3
Does exploitation require user interaction or local access?
No user interaction is required, and the attack vector is network-based. The attacker must still have the required low-privileged account access.