The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 15 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpengine Wpengine advanced Custom Fields |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpengine Wpengine advanced Custom Fields |
Wed, 15 Apr 2026 01:45:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-15T16:01:25.621Z
Reserved: 2026-03-25T13:02:36.082Z
Link: CVE-2026-4812
Updated: 2026-04-15T16:01:19.827Z
Status : Received
Published: 2026-04-15T04:17:48.523
Modified: 2026-04-15T04:17:48.523
Link: CVE-2026-4812
No data.
OpenCVE Enrichment
Updated: 2026-04-15T13:49:14Z
Weaknesses