WordPress Plugin Vulnerabilities
Advanced Custom Fields (ACF®) < 6.8.2 - Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters
Description
The plugin is vulnerable to authorization bypass due to not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and post_content of any post bound to a publicly accessible acf_form() instance by injecting values into the _post_title and _post_content parameters of a form submission request.
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Sarawut Poolkhet (MisterHelloz)
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-05-30 (about 2 months ago)
Added
2026-06-01 (about 2 months ago)
Last Updated
2026-06-01 (about 2 months ago)