Advanced Custom Fields is a widely used WordPress plugin ecosystem centered around its flagship Advanced Custom Fields and ACF Frontend Display products, which serve as foundational tools for extending WordPress content management and form functionality. The vendor's vulnerability profile centers on web-application input-handling and access-control weaknesses—including cross-site scripting, missing authorization checks, unrestricted file uploads, and unsafe deserialization—which are characteristic of plugins that bridge user-facing interfaces with backend data structures and file storage. A meaningful share of the vendor's disclosed vulnerabilities reach serious severity outcomes, and the exposure frequently acquires public exploit availability due to the transparent nature of WordPress plugin development and the broad attack surface presented by internet-facing sites. Current exploitation activity, severity distribution, and exposure breadth are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Advancedcustomfields over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30777MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions. | May 10, 2023 | 6.1 | 53 | NO | YES |
CVE-2015-9479CRITICAL The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.ph | Oct 10, 2019 | 9.8 | 30 | NO | NO |
CVE-2022-2594HIGH The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a defau | Aug 22, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-1196HIGH The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Co | May 2, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-20865HIGH Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may all | Dec 13, 2021 | 7.5 | 26 | NO | NO |
CVE-2022-23183MEDIUM Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacke | Mar 31, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-20867MEDIUM Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which ma | Dec 13, 2021 | 6.5 | 23 | NO | NO |
CVE-2021-20866MEDIUM Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which m | Dec 13, 2021 | 6.5 | 23 | NO | NO |
CVE-2022-40696HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 throu | Jan 8, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-9529MEDIUM The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prev | Nov 15, 2024 | 6.6 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Advancedcustomfields.
Media articles that mention a CVE ID that affects a product developed by Advancedcustomfields — matched by CVE ID, not by vendor name.