Known Vulnerabilities for Advanced Custom Fields Pro by Delicious Brains
Listed below are 8 of the newest known vulnerabilities associated with "Advanced Custom Fields Pro" by "Delicious Brains".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66678 json | Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-49044 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced C... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-46453 json | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest ... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-17580 json | The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Element... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-15262 json | The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputti... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-8809 json | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all ... | Not Provided | 2026-05-28 | 2026-05-29 |
| CVE-2026-8382 json | The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl... | Not Provided | 2026-05-31 | 2026-06-01 |
| CVE-2026-1667 json | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting ... | Not Provided | 2026-07-10 | 2026-07-10 |