CVE · Critical

CVE-2025-13486 — Advanced Custom Fields: Extended [acf-extended] < 0.9.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13486 Advanced Custom Fields: Extended [acf-extended] < 0.9.2 Improper Control of Generation of Code ('Code Injection') Critical 9.8 < 0.9.2 0.9.2 2025-12-02

CVE-2025-13486

The Advanced Custom Fields: Extended plugin for WordPress contains a vulnerability that allows attackers to execute arbitrary code on the server. This occurs when the plugin's prepare_form() function accepts user input, which is then passed through call_user_func_array(), allowing unauthenticated attackers to inject malicious code. As a result, attackers can potentially inject backdoors or create new administrative user accounts, compromising the security of the affected WordPress site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.