Skip to content
WordPress Advanced Custom Fields Extended Plugin Vulnerability

WordPress Advanced Custom Fields Extended Plugin Vulnerability

Ground.News January 21, 2026

A critical security flaw has been discovered in a widely used ACF add-on plugin for WordPress, placing up to 100,000 websites at risk of a full site takeover. The vulnerability affects the Advanced Custom Fields: Extended plugin, an add-on designed to extend the functionality of the popular Advanced Custom Fields ecosystem. An advisory issued the flaw assigns a severity rating of 9.8, emphasizing the serious impact it can have if exploited…

A critical vulnerability has been discovered in a WordPress plugin installed on 100,000 websites. It allows a hacker to create an administrator account on the site and gain complete control. Half of the sites remain vulnerable, even though an update has been deployed.

A vulnerability in an ACF addon plugin installed in 100k websites enables unauthenticated attackers to gain administrator privileges.

WordPress starts the year with a critical vulnerability due to a plugin: Advanced Custom Fileds: Extended, alias ACF Extended. Hackers could use a flaw to recover admin rights even without being authenticated. Problem: This plugin is used by more than 100,000 WordPress sites. Vulnerability is referenced CVE-2025-14533. The flaw comes from misuse of Insert User / Update User on versions 0.9.2.1 and earlier. It appears that there is a lack of acti…

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

Platforms (1)