CVE-2026-80467
largeUnauthenticated Privilege Escalation in Advanced Custom Fields: Extended WordPress Plugin
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 fails to properly manage privileges (CWE-269) when handling its front-end user forms: the role submitted with a registration is not restricted to the roles the form actually offers, and the plugin's safeguard against granting privileged roles is incomplete. An unauthenticated attacker can submit a crafted registration through a site's front-end user form to create an account with elevated capabilities, then escalate that account to administrator. This grants full control over the WordPress site, consistent with the high confidentiality, integrity, and impact ratings. Any WordPress site running the plugin and exposing front-end user forms for registration is affected. No public proof of concept is known, exploitation probability is low (EPSS 0.2%, percentile 12), and the flaw is not in CISA's KEV catalog.
What to do: Update the Advanced Custom Fields: Extended plugin to version 0.9.2.7 or later. Until patched, disable or restrict front-end user registration forms built with the plugin, or require manual approval of new registrations. Also review the user list for recently registered accounts with unexpected editor/administrator roles or elevated capabilities that were not created by an administrator.
| ACF Extended Advanced Custom Fields: Extended (WordPress plugin) | All versions before 0.9.2.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.