CVE · Medium

CVE-2025-15463 — Advanced Custom Fields: Extended [acf-extended] < 0.9.2.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-15463 Advanced Custom Fields: Extended [acf-extended] < 0.9.2.4 Improper Control of Generation of Code ('Code Injection') Medium 6.5 < 0.9.2.4 0.9.2.4 2026-05-12

CVE-2025-15463

The Advanced Custom Fields: Extended plugin for WordPress contains a flaw in its handling of user input, specifically in relation to executing actions and shortcodes. Versions up to 0.9.2.3 are affected by this issue, which can be exploited by unauthorized users to run any shortcode they choose.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.