Cross-site Scripting Vulnerability in Advanced Custom Fields: Font Awesome Field by Justin Kruit
CVE-2026-49044
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-49044?
A Cross-site Scripting (XSS) vulnerability exists in the Advanced Custom Fields: Font Awesome Field plugin, allowing attackers to execute malicious scripts within the user’s browser. This vulnerability impacts all versions from n/a up to 5.0.2, potentially enabling unauthorized access to user data and compromising site integrity. Attackers can exploit this flaw by injecting crafted input, which the application fails to properly neutralize during web page generation. Users are advised to update their installations to protect against possible exploitation.
Affected Version(s)
Advanced Custom Fields: Font Awesome Field <= 5.0.2