HIGH
Advanced Custom Fields
CVE published 2026-09-02
CVE-2026-12526
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 is vulnerable in its front-end Forms module, allowing an unauthenticated attacker to overwrite an administrator's password if the form targets an existing administrator account and maps the password to a visitor-submitted field. This issue arises because the plugin fails to verify that the requester is authorized to edit the targeted use [truncated]