CVE 9.8 CRITICAL

Advanced Custom Fields: Extended 0.9.0.5 – 0.9.1.1 – Unauthenticated Remote Code Execution in prepare_form_CVE-2025-13486

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.

AI Analysis

Unauthenticated Remote Code Execution vulnerability in Advanced Custom Fields: Extended plugin for WordPress via the prepare_form() function

Basic Information

ID CVE-2025-13486
Source Wordfence
Published Dec 3, 2025 at 06:47

Affected Product

Vendor hwk-fr
Product Advanced Custom Fields: Extended
Version 0.9.0.5
Affected Versions hwk-fr Advanced Custom Fields: Extended 0.9.0.5

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor hwk-fr
Product Advanced Custom Fields: Extended
Version 0.9.0.5, 0.9.1.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.