Junglewise Threat Intelligence

CVE-2026-81284: ACF Extended broken access control in contributor role

CVE-2026-81284 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Executive brief

ACF Extended is a WordPress plugin that extends the functionality of Advanced Custom Fields, a popular tool for managing custom data in WordPress sites. The plugin contains an access control vulnerability that allows contributors (lower-privileged users) to view or modify content and data they should not have permission to access. This could lead to unauthorized data exposure or site modification depending on the configuration.

Technical details

A broken access control vulnerability exists in ACF Extended versions 0.9.2.6 and earlier, allowing authenticated users with the contributor role to bypass authorization checks and access or perform actions outside their intended permissions. The vulnerability stems from insufficient permission validation in the plugin's functionality. An attacker with contributor privileges can exploit this through normal plugin interactions without requiring additional network-level access. The impact is limited to unauthorized access to protected data or site functions. A patch is available in version 0.9.2.7 and later.

Affected products

  • Aspen Grove Studios ACF Extended 0.9.2.6 and earlier

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fixed in version 0.9.2.7

References