Known Vulnerabilities for Advanced Custom Fields ACF by WP Engine
Listed below are 7 of the newest known vulnerabilities associated with "Advanced Custom Fields ACF" by "WP Engine".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-80467 json | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-e... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-66678 json | Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-46453 json | Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest ... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-17580 json | The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Element... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-15262 json | The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputti... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-12526 json | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-1667 json | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting ... | Not Provided | 2026-07-10 | 2026-07-10 |