A critical security vulnerability has been identified in the Advanced Custom Fields: Extended (ACF Extended) plugin for WordPress, potentially exposing around 50,000 websites to unauthorized administrative access. This flaw, tracked as CVE-2025-14533, was discovered by security researcher Andrea Bocchetti in December 2025 and reported to Wordfence. The vulnerability arises from improper role enforcement during user creation or updates via the plugin's frontend forms. Specifically, the issue allows unauthenticated users to assign themselves administrative roles, regardless of the field settings, by including a role field in the form. This oversight can lead to complete site compromise, including the creation of administrator accounts, installation of malware, and manipulation of site content. The flaw affects versions up to and including 0.9.2.1 of ACF Extended. A patched version, 0.9.2.2, was released promptly to address the issue. Despite the availability of the update, approximately 50,000 sites remain vulnerable, as indicated by WordPress' official statistics. While there have been no confirmed reports of exploitation, the widespread disclosure of this vulnerability increases the likelihood of cybercriminals probing for and exploiting these weaknesses. Website administrators are strongly advised to update to the latest version of ACF Extended immediately to mitigate potential risks. (wp-firewall.com)
Critical Vulnerability in ACF Extended Plugin Exposes 50,000 WordPress Sites to Potential Takeover
A severe flaw in the ACF Extended plugin allows unauthenticated users to gain administrative access, affecting approximately 50,000 WordPress sites.

Andrew Wallace
Professional Tech Editor
Focuses on professional-grade hardware, software, and enterprise solutions.
React to this story
Related Posts
Mar 3, 2026
Google Addresses 129 Android Security Flaws, Including Critical Zero-Day
Learn about the recent Android security patch addressing critical vulnerabilities, including a Qualcomm zero-day exploit.
Mar 3, 2026
How OAuth Phishing Campaigns are Evolving: What You Need to Know
Microsoft's warning on OAuth phishing highlights new malware risks bypassing traditional defenses. Learn how this affects your security.
Mar 3, 2026
How Perplexity's AI Comet Browser Vulnerability Affects Your Security
A critical zero-click vulnerability in the Perplexity AI Comet browser has raised concerns about password theft without user interaction.
Mar 3, 2026
Impact of Hacktivist Data Breach on ICE and DHS Partnerships
Hacktivists have revealed sensitive data about over 6,000 companies linked to ICE and DHS, raising security concerns.