Junglewise Threat Intelligence

CVE-2026-6415: Advanced Custom Fields: Font Awesome Stored XSS in update_preview

CVE-2026-6415 · Severity: medium · CVSS 6.4 · Published 2026-05-15

Executive brief

The Advanced Custom Fields: Font Awesome plugin for WordPress, which allows site owners to easily add icons to their content, contains a security flaw. An attacker with basic user access (such as a subscriber) can inject malicious scripts into the website. These scripts will run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the update_preview() JavaScript function in versions up to 5.0.2. The vulnerability stems from insufficient input validation of JSON field values and unsafe client-side HTML construction. An authenticated attacker with Subscriber-level permissions or higher can inject arbitrary web scripts into JSON fields. These scripts are then stored and executed in the context of a user's browser session whenever they access the modified page. A patch appears to be available in the plugin's changeset 3525840.

Affected products

  • Matt Keys Advanced Custom Fields: Font Awesome Up to and including 5.0.2

Timeline

  • 2026-05-15: advisory: NVD published the CVE record based on Wordfence data.
  • 2026-05-15: disclosed

References