All 4 CVE vulnerabilities found in Advanced Custom Fields: Extended, with AI-generated Chinese analysis, references, and POCs.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2025-14533 | Advanced Custom Fields: Extended <= 0.9.2.1 - Unauthenticated Privilege Escalation via Insert User Form Action CWE-269 | 9.8 | Critical | 2026-01-20 |
| CVE-2025-13486 | Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form CWE-94 | 9.8 | Critical | 2025-12-03 |
| CVE-2023-5292 | Advanced Custom Fields: Extended <= 0.8.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 | 6.4 | Medium | 2023-10-20 |
| CVE-2021-24865 | Advanced Custom Fields: Extended < 0.8.8.7 - Admin+ SQL Injection CWE-89 | 7.2 | - | 2022-01-24 |
All 4 known CVE vulnerabilities affecting Advanced Custom Fields: Extended with full Chinese analysis, references, and POCs where available.