WP Clinic
Log in Sign up

CVE · Low

CVE-2025-54940 — Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-54940 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3 Improper Control of Generation of Code ('Code Injection') Low 3.4 < 6.4.3 6.4.3 2025-08-08

CVE-2025-54940

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 6.4.2. This is due to the plugin nor properly neutralizing unsafe HTML. This makes it possible for authenticated attackers, with administrator-level access and above, to inject potentially malicious HTML.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.