PT-2026-84603 · WordPress · Advanced Custom Fields: Extended

·

CVE-2026-12526

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Custom Fields: Extended WordPress plugin versions prior to 0.9.2.7
Description The front-end Forms module fails to verify if the requester is authorized to edit a targeted user account during the update-user action. The plugin only performs capability checks when the submitted role is administrator or super admin. If a publicly accessible front-end form is configured to target an administrator account and maps the password to a visitor-submitted field, an unauthenticated visitor can overwrite the administrator's password to take over the account. By default, the action targets the submitting user, meaning exploitation requires the form to be specifically configured to target another account.
Recommendations Update Advanced Custom Fields: Extended WordPress plugin to version 0.9.2.7 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12526

Affected Products

Advanced Custom Fields: Extended