Cross-Site Scripting in Advanced Custom Fields: Font Awesome Field Plugin for WordPress
CVE-2025-14983
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-14983?
The Advanced Custom Fields: Font Awesome Field plugin for WordPress is susceptible to Cross-Site Scripting due to inadequate input sanitization and output escaping. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts, potentially compromising the security of users by executing malicious scripts in their browsers.
Affected Version(s)
Advanced Custom Fields: Font Awesome Field 0 <= 5.0.1