The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpengine Wpengine advanced Custom Fields |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpengine Wpengine advanced Custom Fields |
Wed, 15 Apr 2026 01:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-04-15T01:25:17.540Z
Updated: 2026-04-15T16:01:25.621Z
Reserved: 2026-03-25T13:02:36.082Z
Link: CVE-2026-4812
Updated: 2026-04-15T16:01:19.827Z
Status : Received
Published: 2026-04-15T04:17:48.523
Modified: 2026-04-15T04:17:48.523
Link: CVE-2026-4812
No data.