9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
AI Analysis
Unauthenticated Remote Code Execution vulnerability in Advanced Custom Fields: Extended plugin for WordPress via the prepare_form() function
Basic Information
ID
CVE-2025-13486
Source
Wordfence
Published
Dec 3, 2025 at 06:47
Affected Product
Vendor
hwk-fr
Product
Advanced Custom Fields: Extended
Version
0.9.0.5
Affected Versions
hwk-fr Advanced Custom Fields: Extended 0.9.0.5
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
hwk-fr
Product
Advanced Custom Fields: Extended
Version
0.9.0.5, 0.9.1.1