Executive brief
The Advanced Members for ACF plugin for WordPress, which adds member management features to websites, contains a security flaw that allows logged-in users to delete files from the web server. By deleting critical system files like configuration settings, an attacker can crash the website or potentially take full control of the server. This risk is particularly high because even users with low-level 'Subscriber' accounts can trigger the vulnerability.
Technical details
The vulnerability is classified as an improper limitation of a pathname to a restricted directory (CWE-22) within the 'create_crop' function of the Advanced Members for ACF plugin. The root cause is insufficient validation of user-supplied file paths, allowing authenticated attackers with at least Subscriber-level privileges to specify and delete arbitrary files on the server. By targeting critical WordPress files such as 'wp-config.php', an attacker can force the site into a setup state, which can be leveraged to achieve remote code execution. The vulnerability exists in all versions up to 1.2.5; while a partial patch was introduced in 1.2.5, users are advised to check for subsequent updates that fully address the path validation logic.
Affected products
- danbilabs Advanced Members for ACF up to and including 1.2.5
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched: Partial patch released in version 1.2.5
References
- https://plugins.trac.wordpress.org/browser/advanced-members/tags/1.2.4/core/modules/class-avatar.php
- https://plugins.trac.wordpress.org/browser/advanced-members/tags/1.2.4/core/modules/class-avatar.php
- https://plugins.trac.wordpress.org/browser/advanced-members/trunk/core/modules/class-avatar.php
- https://plugins.trac.wordpress.org/changeset/3479725/
- https://plugins.trac.wordpress.org/changeset/3492372/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/22b63369-c6ea-42e9-bea3-d15837da7732?source=cve