The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 15 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpengine Wpengine advanced Custom Fields |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpengine Wpengine advanced Custom Fields |
Wed, 15 Apr 2026 01:45:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-15T01:25:17.540Z
Reserved: 2026-03-25T13:02:36.082Z
Link: CVE-2026-4812
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-04-15T13:49:14Z
Weaknesses