Impact
The vulnerability in WordPress ACF Extended plugin versions 0.9.2.6 and earlier allows attackers to bypass normal access restrictions, potentially giving them the ability to view, modify, or delete custom fields and configuration settings. This can expose sensitive site data or disrupt site functionality. The weakness is an Access Control error (CWE-862).
Affected Systems
WordPress sites running the ACF Extended plugin version 0.9.2.6 or earlier are affected. This includes any installation where the plugin is active and the vulnerable version is present. The plugin is distributed for WordPress by ACF Extended.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and no EPSS data is available; the vulnerability is not listed in CISA KEV. The likely attack vector is through a web request to the plugin’s management interface by a user with sufficient privileges, since it involves broken access control. While exploitation requires an active account, the risk remains if privileged users are compromised or if the site has inadvertently exposed administrative endpoints. No public exploits have been reported, but the weakness could be leveraged in a targeted attack.
OpenCVE Enrichment