WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Acf Extended?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Acf Extended — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: acf-extended
  • 100000+ instalaciones activas

acfadmincustom fieldsfieldsmeta

Estado de mantenimiento

  • Última versión conocida: 0.9.2.6
  • Requiere PHP: 5.6+
  • PHP máximo soportado (analizado): <8.0

Vulnerabilidades conocidas

6 CVEs conocidos registrados para Acf Extended. Reportadas entre 2021 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-8809 Advanced Custom Fields: Extended [acf-extended] < 0.9.2.6 Gestión incorrecta de privilegios Crítica 9,8 < 0.9.2.6 0.9.2.6 2026-05-28 ✓ corregido en la última versión
CVE-2025-15463 Advanced Custom Fields: Extended [acf-extended] < 0.9.2.4 Control incorrecto de la generación de código (inyección de código) Media 6,5 < 0.9.2.4 0.9.2.4 2026-05-12 ✓ corregido en la última versión
CVE-2025-14533 Advanced Custom Fields: Extended [acf-extended] < 0.9.2.2 Gestión incorrecta de privilegios Crítica 9,8 < 0.9.2.2 0.9.2.2 2026-01-19 ✓ corregido en la última versión
CVE-2025-13486 Advanced Custom Fields: Extended [acf-extended] < 0.9.2 Control incorrecto de la generación de código (inyección de código) Crítica 9,8 < 0.9.2 0.9.2 2025-12-02 ✓ corregido en la última versión
CVE-2023-5292 Advanced Custom Fields: Extended [acf-extended] < 0.8.9.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 0.8.9.4 0.8.9.4 2023-09-29 ✓ corregido en la última versión
CVE-2021-24865 Advanced Custom Fields: Extended [acf-extended] < 0.8.8.7 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,2 < 0.8.8.7 0.8.8.7 2021-12-23 ✓ corregido en la última versión

CVE-2026-8809

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with no authentication or integrity verification — to select a cleanup branch that silently discards all validation errors not prefixed with acfe:. This makes it possible for unauthenticated attackers to suppress both the role allow-list validation error added by acfe_field_user_roles::validate_front_value() and the administrator-role capability guard error added by acfe_module_form_action_user::validate_action(), causing wp_insert_user() to execute with an attacker-supplied administrator role argument and resulting in the creation of a new administrator-level user account. Exploitation requires the target site to expose a public ACFE frontend form configured with a Create User action that maps a role field.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-15463

The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-14533

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can only be exploited if 'role' is mapped to the custom field.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-13486

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-5292

Update the WordPress Advanced Custom Fields: Extended plugin to the latest available version (at least 0.8.9.4). Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Custom Fields: Extended Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 0.8.9.4.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24865

The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Cómo solucionarlo

Mantén Acf Extended actualizado — 0.9.2.6 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.