CVE Database /
CVE-2025-54940
CVE · Low
CVE-2025-54940 — Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-54940
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3 |
Improper Control of Generation of Code ('Code Injection') |
Low
3.4
|
< 6.4.3
|
6.4.3 |
2025-08-08 |
—
|
CVE-2025-54940
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 6.4.2. This is due to the plugin nor properly neutralizing unsafe HTML. This makes it possible for authenticated attackers, with administrator-level access and above, to inject potentially malicious HTML.
Source:
Wordfence
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings