WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Advanced Custom Fields?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Advanced Custom Fields — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: advanced-custom-fields
  • 2000000+ instalaciones activas

acfcustom fieldsfieldsmetarepeater

Estado de mantenimiento

  • Última versión conocida: 6.8.6
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

20 CVEs conocidos registrados para Advanced Custom Fields.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-8382 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2 Falta de control de autorización Media 5,3 < 6.8.2 6.8.2 2026-05-30 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2 Desconocido < 6.8.2 6.8.2 2026-05-27 ✓ corregido en la última versión
CVE-2025-54940 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3 Control incorrecto de la generación de código (inyección de código) Baja 3,4 < 6.4.3 6.4.3 2025-08-08 ✓ corregido en la última versión
CVE-2012-10025 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 Control incorrecto del nombre de archivo en una sentencia include/require de PHP (inclusión remota de archivos PHP / RFI) Desconocido < 3.5.2 3.5.2 2025-08-05 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 Desconocido < 3.5.2 3.5.2 2025-08-05 ✓ corregido en la última versión
CVE-2024-49593 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,3 < 6.3.9 6.3.9 2024-10-17 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9 Desconocido < 6.3.9 6.3.9 2024-10-16 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9 Desconocido < 6.3.9 6.3.9 2024-10-15 ✓ corregido en la última versión

CVE-2026-8382

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and post_content of any post bound to a publicly accessible acf_form() instance by injecting values into the _post_title and _post_content parameters of a form submission request.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.8.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-54940

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 6.4.2. This is due to the plugin nor properly neutralizing unsafe HTML. This makes it possible for authenticated attackers, with administrator-level access and above, to inject potentially malicious HTML.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2012-10025

The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include and execute arbitrary remote PHP code. This leads to remote code execution under the web server’s context, allowing full compromise of the host.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2

<p>WordPress Advanced Custom Fields Plugin <= 3.5.1 is vulnerable to Remote Code Execution (RCE)</p><p>Software: Advanced Custom Fields</p><p>Fixed in version 3.5.2 </p><p>Affected Version <= 3.5.1</p>

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-49593

In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF, then you can follow the process shown at the advancedcustomfields.com blog URL within the References section below.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9

<p>WordPress Advanced Custom Fields Plugin <= 6.3.6.2 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Advanced Custom Fields</p><p>Link: https://wordpress.org/plugins/advanced-custom-fields/#developers</p><p>Affected Version <= 6.3.6.2</p><p>Fixed in version 6.3.6.3 </p>

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9

The Advanced Custom Fields & Secure Custom Fields plugins for WordPress are vulnerable to Stored Cross-Site Scripting via ACF field labels in all versions up to, and including, 6.3.8 & 6.3.6.2 respectively due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Please follow the reference listed in this vulnerability record for instructions on how to update to the latest version of ACF that patches this issue and ensures accessibility to updates moving forward. Special note: only the minified files in Secure Custom Fields have been patched meaning the source build files are still vulnerable.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 30 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-9529 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8 Control incorrecto de la generación de código (inyección de código) Media 6,6 < 6.3.8 6.3.8 2024-10-07 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8 Desconocido < 6.3.8 6.3.8 2024-10-07 ✓ corregido en la última versión
CVE-2024-45429 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 6.3.6 6.3.6 2024-09-04 ✓ corregido en la última versión
CVE-2024-4565 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.0 Control de acceso incorrecto Media 6,5 < 6.3.0 6.3.0 2024-05-30 ✓ corregido en la última versión
CVE-2023-6701 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 6.2.5 6.2.5 2024-01-17 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5 Desconocido < 6.2.5 6.2.5 2024-01-16 ✓ corregido en la última versión
CVE-2023-40068 Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 6.1.0 - <= 6.1.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 6.1.0–6.1.7 6.1.7 2023-08-21 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8 Desconocido < 6.1.8 6.1.8 2023-08-03 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8 Desconocido < 6.1.8 6.1.8 2023-08-03 ✓ corregido en la última versión
CVE-2023-30777 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 6.1.6 6.1.6 2023-05-10 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6 Desconocido < 6.1.6 6.1.6 2023-05-04 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5 Desconocido < 5.12.5 5.12.5 2023-04-04 ✓ corregido en la última versión
CVE-2023-1196 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5 Deserialización de datos no confiables Alta 8,8 < 5.12.5 5.12.5 2023-04-03 ✓ corregido en la última versión
CVE-2022-40696 Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 3.1.1 - <= 6.0.2 Exposición de información sensible a un actor no autorizado Baja 3,7 3.1.1–6.0.2 6.0.2 2022-10-18 ✓ corregido en la última versión
CVE-2022-2594 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.3 Carga de archivos sin restricción de tipo peligroso Alta 8,8 < 5.12.3 5.12.3 2022-07-14 ✓ corregido en la última versión
CVE-2022-23183 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1 Falta de control de autorización Media 6,5 < 5.12.1 5.12.1 2022-03-30 ✓ corregido en la última versión
CVE-2021-20865 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11 Falta de control de autorización Alta 7,5 < 5.11 5.11 2021-12-02 ✓ corregido en la última versión
CVE-2021-20866 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11 Falta de control de autorización Media 6,5 < 5.11 5.11 2021-12-02 ✓ corregido en la última versión
CVE-2021-20867 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1 Falta de control de autorización Media 6,5 < 5.12.1 5.12.1 2021-12-02 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.10 Desconocido < 5.10 5.10 2021-08-25 ✓ corregido en la última versión
CVE-2020-36172 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.8.12 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 5.8.12 5.8.12 2020-06-10 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12 Desconocido < 5.7.12 5.7.12 2019-02-15 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8 Desconocido < 5.7.8 5.7.8 2018-12-10 ✓ corregido en la última versión
CVE-2018-20986 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 5.7.8 5.7.8 2018-12-07 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 1.1.13 Desconocido < 1.1.13 1.1.13 2016-08-08 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 Desconocido < 3.5.2 3.5.2 2013-01-03 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 Desconocido < 3.5.2 3.5.2 2013-01-03 ✓ corregido en la última versión
CVE-2026-4812 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.7.1 Media 5,3 < 6.7.1 6.7.1 0000-00-00 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12 Desconocido < 5.7.12 5.7.12 ✓ corregido en la última versión
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 Desconocido < 3.5.2 3.5.2 ✓ corregido en la última versión

CVE-2024-9529

The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to limited arbitrary function calls via the 'register_meta_box_cb' and 'meta_box_cb' parameters in all versions up to, and including, 6.3.8 (excluding 6.3.6.2) due to insufficient input validation on those parameters. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary functions, like WordPress functions, in custom post types that will execute whenever a user accesses the injected post type. This can be leveraged to trick other users like administrators accessing posts into performing unauthorized actions through functions, and is not a very serious risk for the vast majority of site owners. Please follow the reference listed in this vulnerability record for instructions on how to update to the latest version of ACF that patches this issue and ensures accessibility to updates moving forward. Please note this issue was partially patched in 6.3.8 and 6.3.6.1 - 6.3.6.2, however, was hardened further in 6.3.6.3 and 6.3.9.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-45429

The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field groups in all versions up to, and including, 6.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with the 'capability' setting privilege, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-4565

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to arbitrary custom field access in all versions up to, and including, 6.2.10. This is due to the plugin not properly restricting what post meta can be displayed through the plugin's shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve potentially sensitive information from custom fields.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-6701

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5

Update the WordPress Advanced Custom Fields plugin to the latest available version (at least 6.2.5). Francesco Carlucci discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Custom Fields Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.2.5. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-40068

Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8

The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF post type and taxonomy labels in versions 6.1 to 6.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8

Update the WordPress Advanced Custom Fields plugin to the latest available version (at least 6.1.8). Satoo Nakano, Ryotaro Imamura discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Custom Fields Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.1.8.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-30777

The plugins do not escape the post_status parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6

The Advanced Custom Fields (free & PRO) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_status' parameter in versions 5.8.10 to 5.12.5 and versions 6.0.0 to 6.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5

Update the WordPress Advanced Custom Fields plugin to the latest available version (at least 5.12.5 or 6.1.0). Unknown discovered and reported this PHP Object Injection vulnerability in WordPress Advanced Custom Fields Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 6.1.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-1196

The Advanced Custom Fields plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.0.7 via deserialization of untrusted input in custom field values. This makes it possible for authenticated attackers, with contributor-level permissions, and above to inject a PHP Object. No POP chain appears to be present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-40696

The Advanced Custom Fields plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 6.0.2. While the ACF shortcode ensures that the ACF data being accessed is valid data that has been entered into ACF fields, it may be possible with certain site configurations, that contributor-level users may extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-2594

The plugin allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release. By default WordPress does not allow uploading of .php files so this vulnerability is not easily wormable, but there are many other file types that can be uploaded that can be then used with another exploit to execute code or used in a phishing attack to get a user to download and execute a resource from a "trusted" site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2022-23183

The Advanced Custom Fields plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 5.12. This makes it possible for authenticated attackers with editor access, such as Contributors and above, to view information in the database without the appropriate authorization.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-20865

WordPress Plugin "Advanced Custom Fields" provided by Delicious Brains contains multiple missing authorization vulnerabilities listed below. * Missing authorization related to database browsing (CWE-862) - CVE-2021-20865 * Missing authorization related to user list obtaining (CWE-862) - CVE-2021-20866 * Missing authorization related to field group movement (CWE-862) - CVE-2021-20867 Keitaro Yamazaki of Ierae Security, Inc reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

CVE-2021-20866

WordPress Plugin "Advanced Custom Fields" provided by Delicious Brains contains multiple missing authorization vulnerabilities listed below. * Missing authorization related to database browsing (CWE-862) - CVE-2021-20865 * Missing authorization related to user list obtaining (CWE-862) - CVE-2021-20866 * Missing authorization related to field group movement (CWE-862) - CVE-2021-20867 Keitaro Yamazaki of Ierae Security, Inc reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

CVE-2021-20867

WordPress Plugin "Advanced Custom Fields" provided by Delicious Brains contains multiple missing authorization vulnerabilities listed below. * Missing authorization related to database browsing (CWE-862) - CVE-2021-20865 * Missing authorization related to user list obtaining (CWE-862) - CVE-2021-20866 * Missing authorization related to field group movement (CWE-862) - CVE-2021-20867 Keitaro Yamazaki of Ierae Security, Inc reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.10

Arbitrary ACF Data/Field Groups View and Fields Move vulnerability discovered by Keitaro Yamazaki in WordPress Advanced Custom Fields plugin (versions <= 5.9.9).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2020-36172

The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12

Advanced Custom Fields before 5.7.12 fails to sanitize user-supplied input before passing it to the unserialize() function. This allows low-level authenticated users to call PHP Objects and possibly achieve remote code execution if a usable gadget is present in a plugin or theme installed on the same site as the vulnerable plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8

Authenticated Cross-Site Scripting (XSS) vulnerability found by Loading Kura Kura in WordPress Advanced Custom Fields plugin (versions <= 5.7.7).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2018-20986

According to the vendor: "This release contains a fix to a recently reported XSS vunerability [sic]. This report showed it was possible for a logged in author to save unfiltered HTML within a custom field value. This is something that should not be possible without the unfiltered_html capability."

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 1.1.13

Because of this vulnerability, users can inject JavaScript into pages within /wp-admin/. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2

WordPress Advanced Custom Fields plugin is prone to a remote file inclusion vulnerability. It allows for remote file inclusion and remote code execution via the export.php script. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2

Advanced Custom Fields up to 3.5.1 is vulnerable to Remote Code Execution. The vulnerability allows for remote file inclusion and remote code execution via the export.php script. This exploit only works when the php option allow_url_include is set to On (Default Off).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-4812

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12

Multiple maybe_unserialize calls result with unserialize of user input. Low priviledged users as contributors, but in many cases visitors too

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2

The Advanced Custom Fields WordPress plugin was affected by a Remote File Inclusion security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Advanced Custom Fields actualizado — 6.8.6 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.