Executive brief
The Advanced Custom Fields: Extended WordPress plugin allows unauthenticated attackers to take over administrator accounts when a site exposes a publicly reachable form configured to update existing user accounts. An attacker can overwrite an administrator's password without any authentication, leading to complete account compromise and potential full site takeover.
Technical details
This is an authentication bypass vulnerability (CWE-287) in the front-end Forms module's update-user action. The plugin fails to verify user authorization for targeted account updates; it only checks capabilities when the submitted role is administrator or super_admin, and relies on the default target (the submitting user) which can be overridden via form configuration. An unauthenticated attacker can exploit this by submitting a front-end form that targets an existing administrator account and maps the password field to a visitor-supplied parameter, allowing password reset without authentication. The vulnerability requires specific form configuration (targeting another account with password field exposed), and has been patched in version 0.9.2.7 and later.
Affected products
- Elementor Advanced Custom Fields: Extended before 0.9.2.7
Timeline
- 2026-08-31: disclosed
- 2026-09-02: patched: Version 0.9.2.7 released