Critical Vulnerability in ACF Extended Plugin Threatens 100,000 WordPress Sites

Critical Vulnerability in ACF Extended Plugin Threatens 100,000 WordPress Sites

First seen 22 Jan 2026, 02:59 UTC BleepingcomputerThecyberexpressGround.News 89% similarity 26.6

Article Content

Browse articles
ThreatCluster

A critical security vulnerability has been identified in the Advanced Custom Fields: Extended plugin for WordPress, affecting up to 100,000 websites. The flaw allows unauthenticated attackers to gain administrative permissions, with a severity rating of 9.8 assigned to the vulnerability, tracked as CVE-2025-14533.

ThreatCluster AI How this analysis works

Community

Browse all →