Description
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
Published: 2026-08-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from broken access control in the WordPress plugin Advanced Custom Fields: Font Awesome Field versions 6.1.1 and earlier, allowing an attacker to bypass authorization checks. As a result, an unauthorized user could access or modify sensitive plugin settings or data. The weakness is identified as CWE-862, indicating that the code does not properly enforce access controls. Based on the description, it is inferred that the attacker would need to interact with the plugin’s administrative interface or any endpoint that permits configuration changes.

Affected Systems

The affected product is the Advanced Custom Fields: Font Awesome Field plugin for WordPress, developed by Justin Kruit. Versions up to and including 6.1.1 are impacted. WordPress sites that have this plugin installed without updating to a newer version are susceptible.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk. EPSS is not available, so the current probability of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to exploit the broken access control; based on the description it is inferred that the vulnerability can be leveraged by users who can interact with the plugin’s administrative interface, potentially including authenticated users with low privileges. Based on the description, it is inferred that the attack vector involves interacting with the plugin's administrative interface, possibly via authenticated users with limited privileges. Absence of a publicly known exploit reduces immediate risk, but the lack of proper enforcement of access rights remains a concern.

Generated by OpenCVE AI on August 6, 2026 at 16:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Advanced Custom Fields: Font Awesome Field plugin to version 6.1.2 or later.
  • If an upgrade is not immediately possible, disable or delete the vulnerable plugin to prevent exploitation.
  • Review WordPress user accounts and remove any unused privileged accounts to reduce the number of potential attackers.

Generated by OpenCVE AI on August 6, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Justinkruit
Justinkruit advanced Custom Fields:font Awesome Field
Wordpress
Wordpress wordpress
Vendors & Products Justinkruit
Justinkruit advanced Custom Fields:font Awesome Field
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
Title WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Justinkruit Advanced Custom Fields:font Awesome Field
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T15:35:31.352Z

Reserved: 2026-07-27T14:00:57.628Z

Link: CVE-2026-66678

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:21.353

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-66678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:00:11Z

Weaknesses