CVE · High

CVE-2023-1196 — Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1196 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5 Deserialization of Untrusted Data High 8.8 < 6.1.0 6.1.0 2023-04-03

CVE-2023-1196

The Advanced Custom Fields plugin for WordPress contains a PHP Object Injection vulnerability in versions up to and including 6.0.7 that stems from unsafe deserialization of custom field values. Authenticated users with at least contributor-level access can exploit this flaw to inject malicious PHP objects. While the plugin itself lacks a usable Property-Oriented Programming chain, the presence of such a chain in other installed plugins or themes could enable attackers to perform actions including arbitrary file deletion, unauthorized data access, or remote code execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.