Known Vulnerabilities for Advanced Custom Fields by Tassos.gr
Listed below are 9 of the newest known vulnerabilities associated with "Advanced Custom Fields" by "Tassos.gr".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49044 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced C... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-8809 json | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all ... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-6415 json | The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to ... | Not Provided | 2026-05-15 | 2026-05-15 |
| CVE-2026-4812 json | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosur... | Not Provided | 2026-04-15 | 2026-04-15 |
| CVE-2025-26746 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in caalami Advanced Custom... | Not Provided | 2025-04-15 | 2026-04-23 |
| CVE-2025-15463 json | The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2023-6701 json | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in... | Not Provided | 2024-02-05 | 2026-04-08 |
| CVE-2023-5292 json | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acfe_form' sh... | Not Provided | 2023-10-20 | 2026-04-08 |
| CVE-2022-40696 json | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue... | Not Provided | 2024-01-08 | 2026-04-28 |