PT-2026-84603 · WordPress · Advanced Custom Fields: Extended
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advanced Custom Fields: Extended WordPress plugin versions prior to 0.9.2.7
Description
The front-end Forms module fails to verify if the requester is authorized to edit a targeted user account during the
update-user action. The plugin only performs capability checks when the submitted role is administrator or super admin. If a publicly accessible front-end form is configured to target an administrator account and maps the password to a visitor-submitted field, an unauthenticated visitor can overwrite the administrator's password to take over the account. By default, the action targets the submitting user, meaning exploitation requires the form to be specifically configured to target another account.Recommendations
Update Advanced Custom Fields: Extended WordPress plugin to version 0.9.2.7 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Custom Fields: Extended