CVE Database /
CVE-2025-54940
CVE · Low
CVE-2025-54940 — Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-54940
|
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3 |
Improper Control of Generation of Code ('Code Injection') |
Low
3.4
|
< 6.4.3
|
6.4.3 |
2025-08-08 |
—
|
CVE-2025-54940
The Advanced Custom Fields (ACF) plugin for WordPress has a vulnerability that allows HTML injection in all versions up to 6.4.2. Due to inadequate sanitization of user inputs, authenticated administrators can inject harmful HTML code.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings