Unauthorized Access Vulnerability in Advanced Custom Fields Plugin by WordPress
CVE-2026-80467

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-80467?

The Advanced Custom Fields: Extended plugin for WordPress prior to version 0.9.2.7 has a vulnerability that allows unauthenticated users to submit roles through front-end user forms. This critical flaw means that the plugin does not properly restrict role submissions to the predefined roles offered by the form, leading to the potential for users to register accounts with elevated privileges. As a result, these users could escalate their privileges to that of an administrator, posing a significant risk to the security of the WordPress installation.

Affected Version(s)

Advanced Custom Fields: Extended 0.9.2.2 < 0.9.2.7

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman
WPScan
.