Description
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Published: 2026-08-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Update Plugin
AI Analysis

Impact

The vulnerability in WordPress ACF Extended plugin versions 0.9.2.6 and earlier allows attackers to bypass normal access restrictions, potentially giving them the ability to view, modify, or delete custom fields and configuration settings. This can expose sensitive site data or disrupt site functionality. The weakness is an Access Control error (CWE-862).

Affected Systems

WordPress sites running the ACF Extended plugin version 0.9.2.6 or earlier are affected. This includes any installation where the plugin is active and the vulnerable version is present. The plugin is distributed for WordPress by ACF Extended.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity, and no EPSS data is available; the vulnerability is not listed in CISA KEV. The likely attack vector is through a web request to the plugin’s management interface by a user with sufficient privileges, since it involves broken access control. While exploitation requires an active account, the risk remains if privileged users are compromised or if the site has inadvertently exposed administrative endpoints. No public exploits have been reported, but the weakness could be leveraged in a targeted attack.

Generated by OpenCVE AI on August 28, 2026 at 16:46 UTC.

Remediation

Vendor Solution

Update the WordPress ACF Extended Plugin to the latest available version (at least 0.9.2.7).


OpenCVE Recommended Actions

  • Apply the vendor‑released patch by upgrading to ACF Extended 0.9.2.7 or later.
  • Remove any remaining copies of the older ACF Extended plugin files from the server to prevent accidental rollback.
  • Restrict access to the plugin’s configuration interface by ensuring only trusted administrators have the necessary WordPress capabilities.

Generated by OpenCVE AI on August 28, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Acf Extended
Acf Extended acf Extended
Wordpress
Wordpress wordpress
Vendors & Products Acf Extended
Acf Extended acf Extended
Wordpress
Wordpress wordpress

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Title WordPress ACF Extended plugin <= 0.9.2.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Acf Extended Acf Extended
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-28T18:35:55.627Z

Reserved: 2026-08-26T17:33:24.196Z

Link: CVE-2026-81284

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T16:18:29.120

Modified: 2026-08-28T20:20:09.657

Link: CVE-2026-81284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:31:53Z

Weaknesses