Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 07 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 07 Aug 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Advanced Custom Fields
Advanced Custom Fields advanced Custom Fields Wordpress Plugin Wordpress Wordpress wordpress |
|
Vendors & Products |
Advanced Custom Fields
Advanced Custom Fields advanced Custom Fields Wordpress Plugin Wordpress Wordpress wordpress |
Tue, 05 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include and execute arbitrary remote PHP code. This leads to remote code execution under the web server’s context, allowing full compromise of the host. | |
Title | WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion | |
Weaknesses | CWE-98 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-08-07T15:12:47.309Z
Reserved: 2025-08-05T15:43:27.678Z
Link: CVE-2012-10025

Updated: 2025-08-07T15:12:35.883Z

Status : Awaiting Analysis
Published: 2025-08-05T20:15:33.193
Modified: 2025-08-07T16:15:28.213
Link: CVE-2012-10025

No data.

Updated: 2025-08-06T15:12:52Z