CVE-2024-28000 is a vulnerability tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 20, 2026; most recent activity January 20, 2026.
A critical security vulnerability has been identified in the Advanced Custom Fields: Extended plugin for WordPress, affecting up to 100,000 websites. The flaw allows unauthenticated attackers to gain administrative…