PatchSiren

Advanced Custom Fields CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Advanced Custom Fields CVE published 2026-09-02

CVE-2026-12526

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 is vulnerable in its front-end Forms module, allowing an unauthenticated attacker to overwrite an administrator's password if the form targets an existing administrator account and maps the password to a visitor-submitted field. This issue arises because the plugin fails to verify that the requester is authorized to edit the targeted use [truncated]