• News/
  • https://www.bleepingcomputer.com/news/security/acf-plugin-bug-gives-hackers-admin-on-50-000-wordpress-sites/

ACF plugin bug gives hackers admin on 50,000 WordPress sites

BleepingComputer
·
Bill Toulas
·
Published Jan 20, 2026
·
Updated

A critical-severity vulnerability in the Advanced Custom Fields: Extended (ACF Extended) plugin for WordPress can be exploited remotely by unauthenticated attackers to obtain administrative permissions. ACF Extended, currently active on 100,000 websites, is a specialized plugin that extends the capabilities of the Advanced Custom Fields (ACF) plugin with features for developers and advanced site builders. The vulnerability, tracked as CVE-2025-14533, can be leveraged for admin privileges by abusing the plugin’s ‘Insert User / Update User’ form action, in versions of ACF Extended 0.9.2.1 and earlier. The flaw arises from the lack of enforcement of role restrictions during form-based user creation or updates, and exploitation works even when role limitations are appropriately configured in the field settings. "In the vulnerable version [of the plugin], there are no restrictions for form fields, so the user's role can be set arbitrarily, even to 'administrator', regardless of the field settings, if there is a role field added to the form," Wordfence explains. "As with any privilege escalation vulnerability, this can be used for complete site compromise," the researchers warn. Although the outcome from exploiting the flaw is severe, Wordfence notes that the issue is only exploitable on sites that explicitly use a ‘Create User’ or ‘Update User’ form with a role field mapped. CVE-2025-14533 was discovered by security researcher Andrea Bocchetti, who, on December 10, 2025, submitte...

Read full article

Affected Software

1 affected component
WordPress Advanced Custom Fields: Extended>=0.0, <=0.9.2.1

Frequently Asked Questions

1

Which ACF Extended versions are affected by CVE-2025-14533?

The vulnerability affects ACF Extended version 0.9.2.1 and earlier. The plugin is currently active on 100,000 websites.

2

How can an attacker gain administrator privileges through this flaw?

An unauthenticated remote attacker can abuse the plugin's “Insert User / Update User” form action to set a user's role arbitrarily, including to administrator. Exploitation requires a role field to be added to the form.

3

Do configured role restrictions prevent exploitation?

No. The flaw results from role restrictions not being enforced during form-based user creation or updates, so exploitation can work even when role limitations are configured in the field settings.

4

What is the potential impact of successful exploitation?

Successful exploitation can grant administrative permissions and lead to complete site compromise.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203