Home

Description

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.

PUBLISHED Reserved 2025-11-20 | Published 2025-12-03 | Updated 2025-12-03 | Assigner Wordfence




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-94 Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

0.9.0.5 (semver)
affected

Timeline

2025-11-20:Vendor Notified
2025-12-02:Disclosed

Credits

Marcin Dudek finder

References

www.wordfence.com/...-53e6-4ebe-b3d0-285908b722c9?source=cve

plugins.trac.wordpress.org/changeset/3400134/acf-extended

cve.org (CVE-2025-13486)

nvd.nist.gov (CVE-2025-13486)