PLUGIN SECURITY

Is Advanced Custom Fields safe?

ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.

What this plugin does

  • Slug: advanced-custom-fields
  • Author: WP Engine
  • 2000000+ active installs
  • 90/100 rating (1438 reviews on wordpress.org)
  • 75911300 all-time downloads
  • On WordPress.org since 2011-03-25

acfcustom fieldsfieldsmetarepeater

Maintenance status

  • Latest known version: 6.8.7
  • Last updated: 2026-08-27 8:27pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

20 known CVEs on file for Advanced Custom Fields.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8382 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2 Missing Authorization Medium 5.3 < 6.8.2 6.8.2 2026-05-30 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2 Unknown < 6.8.2 6.8.2 2026-05-27 ✓ fixed in latest
CVE-2025-54940 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3 Improper Control of Generation of Code ('Code Injection') Low 3.4 < 6.4.3 6.4.3 2025-08-08 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 Unknown < 3.5.2 3.5.2 2025-08-05 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9 Unknown < 6.3.9 6.3.9 2024-10-16 ✓ fixed in latest
CVE-2024-49593 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.3 < 6.3.9 6.3.9 2024-10-15 ✓ fixed in latest
CVE-2024-9529 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8 Improper Control of Generation of Code ('Code Injection') Medium 6.6 < 6.3.8 6.3.8 2024-10-07 ✓ fixed in latest
CVE-2024-45429 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 6.3.6 6.3.6 2024-09-04 ✓ fixed in latest
+ 31 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4565 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.0 Improper Access Control Medium 6.5 < 6.3.0 6.3.0 2024-05-30 ✓ fixed in latest
CVE-2023-6701 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.2.5 6.2.5 2024-01-17 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5 Unknown < 6.2.5 6.2.5 2024-01-16 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8 Unknown < 6.1.8 6.1.8 2023-08-03 ✓ fixed in latest
CVE-2023-40068 Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 6.1.0 - <= 6.1.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 6.1.0–6.1.7 6.1.7 2023-08-03 ✓ fixed in latest
CVE-2023-30777 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 6.1.6 6.1.6 2023-05-04 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5 Unknown < 5.12.5 5.12.5 2023-04-04 ✓ fixed in latest
CVE-2023-1196 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5 Deserialization of Untrusted Data High 8.8 < 6.1.0 6.1.0 2023-04-03 ✓ fixed in latest
CVE-2022-40696 Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 3.1.1 - <= 6.0.2 Exposure of Sensitive Information to an Unauthorized Actor Low 3.7 3.1.1–6.0.2 6.0.2 2022-10-18 ✓ fixed in latest
CVE-2022-2594 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.3 Unrestricted Upload of File with Dangerous Type High 8.8 < 5.12.3 5.12.3 2022-07-14 ✓ fixed in latest
CVE-2022-23183 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1 Missing Authorization Medium 6.5 < 5.12.1 5.12.1 2022-03-30 ✓ fixed in latest
CVE-2021-20865, CVE-2021-20866, CVE-2021-20867 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11 Missing Authorization High 7.5 < 5.11 5.11 2021-12-02 ✓ fixed in latest
CVE-2021-20866 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11 Missing Authorization Medium 6.5 < 5.11 5.11 2021-12-02 ✓ fixed in latest
CVE-2021-20867 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1 Missing Authorization Medium 6.5 < 5.12.1 5.12.1 2021-12-02 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.10 Unknown < 5.10 5.10 2021-08-25 ✓ fixed in latest
CVE-2020-36172 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.8.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.8.12 5.8.12 2020-06-10 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12 Unknown < 5.7.12 5.7.12 2019-02-15 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8 Unknown < 5.7.8 5.7.8 2018-12-10 ✓ fixed in latest
CVE-2018-20986 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.7.8 5.7.8 2018-12-07 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 1.1.13 Unknown < 1.1.13 1.1.13 2016-08-08 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 Unknown < 3.5.2 3.5.2 2013-01-03 ✓ fixed in latest
CVE-2012-10025 Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Unknown < 3.5.2 3.5.2 2013-01-03 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.7.1 Medium 5.3 < 6.7.1 6.7.1 0000-00-00 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12 Unknown < 5.7.12 5.7.12 ✓ fixed in latest
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 Unknown < 3.5.2 3.5.2 ✓ fixed in latest
Advanced Custom Fields <= 3.5.1 - Remote File Inclusion Unknown < 3.5.2 3.5.2 ✓ fixed in latest
Advanced Custom Fields < 5.7.12 - Unserialize of user input Unknown < 5.7.12 5.7.12 ✓ fixed in latest
CVE-2023-30777 Advanced Custom Fields < 6.1.6 - Reflected XSS Unknown < 6.1.6 6.1.6 ✓ fixed in latest
CVE-2024-9529 Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution Unknown < 6.3.6.3 6.3.6.3 ✓ fixed in latest
CVE-2026-4812 Advanced Custom Fields (ACF®) < 6.7.1 - Unauthenticated Arbitrary Post/Page Disclosure via AJAX Field Query Parameters Unknown < 6.7.1 6.7.1 ✓ fixed in latest
Advanced Custom Fields (ACF®) < 6.8.2 - Unauthenticated Arbitrary Field Value Update via Front-End Form Unknown < 6.8.2 6.8.2 ✓ fixed in latest

How to fix it

Keep Advanced Custom Fields updated — 6.8.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.