ZeroHour

CVE-2026-80467

large

Unauthenticated Privilege Escalation in Advanced Custom Fields: Extended WordPress Plugin

CVSS 3.1
8.1 high
EPSS
<1%p12
Published
()
Modified
AI analysis

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 fails to properly manage privileges (CWE-269) when handling its front-end user forms: the role submitted with a registration is not restricted to the roles the form actually offers, and the plugin's safeguard against granting privileged roles is incomplete. An unauthenticated attacker can submit a crafted registration through a site's front-end user form to create an account with elevated capabilities, then escalate that account to administrator. This grants full control over the WordPress site, consistent with the high confidentiality, integrity, and impact ratings. Any WordPress site running the plugin and exposing front-end user forms for registration is affected. No public proof of concept is known, exploitation probability is low (EPSS 0.2%, percentile 12), and the flaw is not in CISA's KEV catalog.

What to do: Update the Advanced Custom Fields: Extended plugin to version 0.9.2.7 or later. Until patched, disable or restrict front-end user registration forms built with the plugin, or require manual approval of new registrations. Also review the user list for recently registered accounts with unexpected editor/administrator roles or elevated capabilities that were not created by an administrator.

Affected
ACF Extended Advanced Custom Fields: Extended (WordPress plugin)All versions before 0.9.2.7
Estimated exposure
largeon the order of 100,000 WordPress sites run the plugin, though only sites that expose its front-end user registration forms are actually exploitable — Estimate based on the plugin's standing as a widely used companion to Advanced Custom Fields with roughly six-figure wordpress.org active-install counts, noting that only installs using the front-end user form feature are exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.

Ecosystems
WordPress
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.