Junglewise Threat Intelligence

CVE-2025-15463: ACFE Advanced Custom Fields: Extended arbitrary shortcode execution

CVE-2025-15463 · Severity: medium · CVSS 6.5 · Published 2026-05-12

Technologies: ACF Extended Advanced Custom Fields: Extended. Vendors: ACF Extended.

Executive brief

The Advanced Custom Fields: Extended plugin for WordPress, which provides enhanced form and field management tools, contains a security flaw that allows unauthorized users to execute arbitrary shortcodes. This could allow an attacker to access sensitive information or perform unauthorized actions on the website by exploiting how the plugin processes form data. The vulnerability affects all versions of the plugin up to and including 0.9.2.3.

Technical details

The Advanced Custom Fields: Extended (ACFE) plugin for WordPress is vulnerable to arbitrary shortcode execution due to a lack of input validation in the form rendering and email action modules. Specifically, the software allows unauthenticated users to trigger actions that pass unvalidated values into the WordPress 'do_shortcode' function. An attacker can exploit this by submitting crafted requests to the front-end form rendering components or email action handlers. This can lead to the execution of any registered shortcode on the site, potentially resulting in information disclosure or further exploitation depending on the available shortcodes. The vulnerability is present in versions up to and including 0.9.2.3.

Affected products

  • ACFE Advanced Custom Fields: Extended Up to, and including, 0.9.2.3

Timeline

  • 2026-05-12: disclosed: Initial publication of the CVE record.
  • 2026-05-12: advisory: Wordfence published the vulnerability details.

References

Related threats