CVE-2023-1196
The Advanced Custom Fields plugin for WordPress contains a PHP Object Injection vulnerability in versions up to and including 6.0.7 that stems from unsafe deserialization of custom field values. Authenticated users with at least contributor-level access can exploit this flaw to inject malicious PHP objects. While the plugin itself lacks a usable Property-Oriented Programming chain, the presence of such a chain in other installed plugins or themes could enable attackers to perform actions including arbitrary file deletion, unauthorized data access, or remote code execution.
Based on public CVE data (MITRE/NVD).