Description
The ACF On-The-Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the acfg_update_fields() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary post titles, descriptions, and ACF values.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31677 | The ACF On-The-Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the acfg_update_fields() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary post titles, descriptions, and ACF values. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ACF On-The-Go <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Update | |
| Weaknesses | CWE-862 |
Fri, 27 Feb 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress acf-on-the-go
|
|
| CPEs | cpe:2.3:a:wordpress:acf-on-the-go:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Wordpress acf-on-the-go
|
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:49:54.764Z
Reserved: 2024-03-28T22:20:10.085Z
Link: CVE-2024-3071
Updated: 2024-08-01T19:32:42.541Z
Status : Deferred
Published: 2024-05-02T17:15:22.330
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-3071
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:43Z
Weaknesses
EUVD