{"error":0,"message":null,"data":{"name":"Advanced Custom Fields: Extended PRO","plugin":"acf-extended-pro","link":"https:\/\/www.acf-extended.com\/","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"35b0ac27b8d99f56410b7f530d6b917bd6e9b7bea633d1c447e92e4451b12fb7","name":"Advanced Custom Fields: Extended PRO [acf-extended-pro] < 0.9.2.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.2.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ca3ca189de4cfbbe30247b4a658f8acac91367b8","name":"Advanced Custom Fields: Extended PRO <= 0.9.2.6 - Unauthenticated Remote Code Execution via Dynamic Render Field Type","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/acf-extended-pro\/advanced-custom-fields-extended-pro-0926-unauthenticated-remote-code-execution-via-dynamic-render-field-type","description":"The Advanced Custom Fields: Extended PRO plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 0.9.2.6 via the render_field function. This is due to insufficient validation of form configuration parameters before merging into field settings and passing to call_user_func_array in the render_field method. This makes it possible for unauthenticated attackers to call arbitrary WordPress functions with controlled arguments. Method 1 requires the administrator to enable the non-default 'shortcode_preview' setting for the target form, while Method 2 requires the server environment to lack OpenSSL functions, causing ACF Pro's acf_decrypt to fall back to unverified base64 decoding.","date":null}],"impact":[]},{"uuid":"3894672458e7719cff7612be60d25880468d022e82d2d956c73752f235d2de60","name":"Advanced Custom Fields: Extended PRO [acf-extended-pro] < 0.9.2.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.2.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"829c1e637e1740ce2d4cfc78325e205e555379b5","name":"WordPress Advanced Custom Fields: Extended PRO Plugin <= 0.9.2.6 is vulnerable to a high priority Remote Code Execution (RCE)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/acf-extended-pro\/vulnerability\/wordpress-advanced-custom-fields-extended-pro-plugin-0-9-2-6-unauthenticated-remote-code-execution-vulnerability","description":"<p>WordPress Advanced Custom Fields: Extended PRO Plugin <= 0.9.2.6 is vulnerable to a high priority Remote Code Execution (RCE)<\/p><p>Software: Advanced Custom Fields: Extended PRO<\/p><p>Fixed in version 0.9.2.7 <\/p><p>Affected Version <= 0.9.2.6<\/p><p>CVE: Unknown<\/p>","date":"2026-09-15"}],"impact":[]}]},"updated":"1789536466"}