WP Clinic
Log in Sign up

CVE · Medium

CVE-2026-8382 — Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8382 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2 Missing Authorization Medium 5.3 < 6.8.2 6.8.2 2026-05-30

CVE-2026-8382

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and post_content of any post bound to a publicly accessible acf_form() instance by injecting values into the _post_title and _post_content parameters of a form submission request.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.