PLUGIN SECURITY
Is Advanced Custom Fields safe?
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
What this plugin does
- Slug:
advanced-custom-fields - Author: WP Engine
- 2000000+ active installs
- 90/100 rating (1438 reviews on wordpress.org)
- 75911300 all-time downloads
- On WordPress.org since 2011-03-25
acfcustom fieldsfieldsmetarepeater
Maintenance status
- Latest known version: 6.8.7
- Last updated: 2026-08-27 8:27pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
20 known CVEs on file for Advanced Custom Fields.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-8382 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2 | Missing Authorization | Medium 5.3 | < 6.8.2 | 6.8.2 | 2026-05-30 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2 | — | Unknown | < 6.8.2 | 6.8.2 | 2026-05-27 | ✓ fixed in latest |
| CVE-2025-54940 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3 | Improper Control of Generation of Code ('Code Injection') | Low 3.4 | < 6.4.3 | 6.4.3 | 2025-08-08 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 | — | Unknown | < 3.5.2 | 3.5.2 | 2025-08-05 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9 | — | Unknown | < 6.3.9 | 6.3.9 | 2024-10-16 | ✓ fixed in latest |
| CVE-2024-49593 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.3 | < 6.3.9 | 6.3.9 | 2024-10-15 | ✓ fixed in latest |
| CVE-2024-9529 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.8 | Improper Control of Generation of Code ('Code Injection') | Medium 6.6 | < 6.3.8 | 6.3.8 | 2024-10-07 | ✓ fixed in latest |
| CVE-2024-45429 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 6.3.6 | 6.3.6 | 2024-09-04 | ✓ fixed in latest |
+ 31 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-4565 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.3.0 | Improper Access Control | Medium 6.5 | < 6.3.0 | 6.3.0 | 2024-05-30 | ✓ fixed in latest |
| CVE-2023-6701 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.2.5 | 6.2.5 | 2024-01-17 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.2.5 | — | Unknown | < 6.2.5 | 6.2.5 | 2024-01-16 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.8 | — | Unknown | < 6.1.8 | 6.1.8 | 2023-08-03 | ✓ fixed in latest |
| CVE-2023-40068 | Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 6.1.0 - <= 6.1.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | 6.1.0–6.1.7 | 6.1.7 | 2023-08-03 | ✓ fixed in latest |
| CVE-2023-30777 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.1.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 6.1.6 | 6.1.6 | 2023-05-04 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5 | — | Unknown | < 5.12.5 | 5.12.5 | 2023-04-04 | ✓ fixed in latest |
| CVE-2023-1196 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.5 | Deserialization of Untrusted Data | High 8.8 | < 6.1.0 | 6.1.0 | 2023-04-03 | ✓ fixed in latest |
| CVE-2022-40696 | Advanced Custom Fields (ACF®) [advanced-custom-fields] >= 3.1.1 - <= 6.0.2 | Exposure of Sensitive Information to an Unauthorized Actor | Low 3.7 | 3.1.1–6.0.2 | 6.0.2 | 2022-10-18 | ✓ fixed in latest |
| CVE-2022-2594 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.3 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 5.12.3 | 5.12.3 | 2022-07-14 | ✓ fixed in latest |
| CVE-2022-23183 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1 | Missing Authorization | Medium 6.5 | < 5.12.1 | 5.12.1 | 2022-03-30 | ✓ fixed in latest |
| CVE-2021-20865, CVE-2021-20866, CVE-2021-20867 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11 | Missing Authorization | High 7.5 | < 5.11 | 5.11 | 2021-12-02 | ✓ fixed in latest |
| CVE-2021-20866 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.11 | Missing Authorization | Medium 6.5 | < 5.11 | 5.11 | 2021-12-02 | ✓ fixed in latest |
| CVE-2021-20867 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.12.1 | Missing Authorization | Medium 6.5 | < 5.12.1 | 5.12.1 | 2021-12-02 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.10 | — | Unknown | < 5.10 | 5.10 | 2021-08-25 | ✓ fixed in latest |
| CVE-2020-36172 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.8.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.8.12 | 5.8.12 | 2020-06-10 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12 | — | Unknown | < 5.7.12 | 5.7.12 | 2019-02-15 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8 | — | Unknown | < 5.7.8 | 5.7.8 | 2018-12-10 | ✓ fixed in latest |
| CVE-2018-20986 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.7.8 | 5.7.8 | 2018-12-07 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 1.1.13 | — | Unknown | < 1.1.13 | 1.1.13 | 2016-08-08 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 | — | Unknown | < 3.5.2 | 3.5.2 | 2013-01-03 | ✓ fixed in latest |
| CVE-2012-10025 | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | Unknown | < 3.5.2 | 3.5.2 | 2013-01-03 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.7.1 | — | Medium 5.3 | < 6.7.1 | 6.7.1 | 0000-00-00 | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 5.7.12 | — | Unknown | < 5.7.12 | 5.7.12 | — | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) [advanced-custom-fields] < 3.5.2 | — | Unknown | < 3.5.2 | 3.5.2 | — | ✓ fixed in latest |
| — | Advanced Custom Fields <= 3.5.1 - Remote File Inclusion | — | Unknown | < 3.5.2 | 3.5.2 | — | ✓ fixed in latest |
| — | Advanced Custom Fields < 5.7.12 - Unserialize of user input | — | Unknown | < 5.7.12 | 5.7.12 | — | ✓ fixed in latest |
| CVE-2023-30777 | Advanced Custom Fields < 6.1.6 - Reflected XSS | — | Unknown | < 6.1.6 | 6.1.6 | — | ✓ fixed in latest |
| CVE-2024-9529 | Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution | — | Unknown | < 6.3.6.3 | 6.3.6.3 | — | ✓ fixed in latest |
| CVE-2026-4812 | Advanced Custom Fields (ACF®) < 6.7.1 - Unauthenticated Arbitrary Post/Page Disclosure via AJAX Field Query Parameters | — | Unknown | < 6.7.1 | 6.7.1 | — | ✓ fixed in latest |
| — | Advanced Custom Fields (ACF®) < 6.8.2 - Unauthenticated Arbitrary Field Value Update via Front-End Form | — | Unknown | < 6.8.2 | 6.8.2 | — | ✓ fixed in latest |
How to fix it
Keep Advanced Custom Fields updated — 6.8.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Meta Box — 500000+ active installs — 96/100 (165) — max PHP 8.4
- Checkout Field Editor (Checkout Manager) for WooCommerce — 400000+ active installs — 98/100 (1056) — max PHP 8.4
- ACF Content Analysis for Yoast SEO — 100000+ active installs — 82/100 (35) — max PHP 8.4
- Advanced Custom Fields: Extended — 100000+ active installs — 96/100 (132) — max PHP <8.0
- Admin Columns — 100000+ active installs — 98/100 (1651)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.