WordPress Plugin Vulnerabilities

Advanced Custom Fields (ACF®) < 6.8.2 - Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters

Description

The plugin is vulnerable to authorization bypass due to not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and post_content of any post bound to a publicly accessible acf_form() instance by injecting values into the _post_title and _post_content parameters of a form submission request.

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Sarawut Poolkhet (MisterHelloz)
Verified
No

Timeline

Publicly Published
2026-05-30 (about 2 months ago)
Added
2026-06-01 (about 2 months ago)
Last Updated
2026-06-01 (about 2 months ago)

Other