CVE-2025-14533Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can only be exploited if 'role' is mapped to the custom field.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 1 mentions (2026-01-28); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-02-04: 1Mentions · 2026-02-06: 1Mentions · 2026-02-17: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-17: 101-2801-2902-0402-0602-17
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-01-291
Disclosure1
2026-02-041
Patch1
2026-02-061
Patch1
2026-02-171
Disclosure1
Full discourse5 posts
  • iototsecnews@iototsecnews
    Disclosure

    WordPress Advanced Custom Fields の脆弱性 CVE-2025-14533 が FIX:Web サイトの乗っ取りリスク https://iototsecnews.jp/2026/01/20/wordpress-plugin-vulnerability-exposes-100000-sites-to-privilege-escalation-attacks/ WordPress の人気プラグイン Advanced Custom Fields: Extended に、Web サイトの管理者権限を乗っ取れてしまう、ききわめて深刻な脆弱性 CVE-2025-14533 が見つかりました。この問題の原因は、ユーザー登録フォームから送られてくる “権限” (ロール) の情報を、プログラム側で正しく制限/検証していなかったことにあります。 このプラグインを使うと、独自のユーザー登録フォームを簡単に作成できます。本来であれば、一般ユーザー (subscriber) としての登録に制限すべきですが、脆弱なバージョン (0.9.2.1 以前) では、攻撃者が通信内容を少し細工して自分を管理者 (administrator) として登録してほしいとリクエストを送るだけで、その通りの権限を持つアカウントが作成されてしまいます。 管理者権限を奪われると、Web サイト内の情報を盗まれるだけでなく、サイト全体を書き換えられたり、ウイルスを配布する踏み台にされたりと、取り返しのつかない被害に遭う恐れがあります。ご利用のチームは、ご注意ください。よろしければ、WordPress での検索結果も、ご参照ください。 #AdvancedCustomFields #CVE202514533 #Vulnerability #WordPress

    Post summary

    The post reports the discovery of CVE‑2025‑14533 in WordPress Advanced Custom Fields, detailing how unverified role assignment in a registration form can lead to full site takeover, but it does not provide a PoC, exploit code, or evidence of active attacks.

    01000152
    485 followersView on X
  • y1 uda@abyo software@y1uda
    Disclosure

    CVE-2025-14533: ACF Extendedの権限昇格(10万サイト影響) [CVSS 9.8 Critical] | Nyambush セキュリティブログ https://nyambush.app/blog/wp-acfe-privesc #Nyambush #WordPress #WPSec #セキュリティ

    Post summary

    The blog post announces CVE-2025-14533, a critical privilege‑escalation flaw in ACF Extended that could impact roughly 100,000 WordPress sites, and rates it CVSS 9.8.

    0000077
    175 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical #WordPress Vulnerability — CVE-2025-14533 A severe privilege escalation flaw in the Advanced Custom Fields: Extended plugin (≤ 0.9.2.1) lets unauthenticated attackers assign themselves administrator roles during user registration when a role field is mapped — risking full site takeover. https://nvd.nist.gov/vuln/detail/CVE-2025-14533 ⚠️ Severity: 9.8 – CRITICAL (remote, no login required) 🔧 Fix: • Update ACF Extended to v0.9.2.2 or later immediately • Audit user roles for unauthorized admin accounts • Remove or restrict unnecessary role fields in frontend forms Detect malware or unauthorized changes before attackers can exploit them: 👉 https://quttera.com/wordpress-malware-scanner Secure your website with full perimeter security. #WordPress #CVE #PrivilegeEscalation #PluginSecurity #eCommerceSecurity #WebSecurity #FullPerimeterSecurity #MalwareDetection

    Post summary

    CVE-2025-14533 is a critical privilege‑escalation flaw in ACF Extended (≤ 0.9.2.1) that allows unauthenticated attackers to gain administrator rights; updating to 0.9.2.2 or later is mandatory to mitigate the risk.

    0000057
    37 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical WordPress Vulnerability — CVE-2025-14533 A flaw in the Advanced Custom Fields: Extended plugin (≤ 0.9.2.1) allows unauthenticated attackers to self-assign administrator rights during user registration when a role field is mapped — granting full control of the site. https://nvd.nist.gov/vuln/detail/CVE-2025-14533 Severity: 9.8 CRITICAL (no login needed; complete compromise possible) ⚠️ Fix: Update ACF Extended to v0.9.2.2 or later immediately • Review user registration forms for role fields • Audit for unauthorized admin accounts 🛡️ Prevent privilege escalations before they hit production: 👉 https://quttera.com/wordpress-malware-scanner Secure your website with full perimeter security #WordPress #CVE #PrivilegeEscalation #PluginSecurity #CyberSecurity #FullPerimeterSecurity #eCommerceSecurity #Malware #CVE

    Post summary

    A critical flaw in the ACF Extended WordPress plugin allows unauthenticated users to gain admin rights; the advisory urges an immediate plugin update to v0.9.2.2 or later, alongside review and audit of registration forms.

    0000050
    37 followersView on X
  • HostingTG@HostingTG
    Disclosure

    ⚠️ Vulnerabilidad crítica en ACF Extended (CVE-2025-14533): escalada de privilegios a administrator en versiones ≤ 0.9.2.1 cuando usas formularios front-end de usuario con el campo role mapeado. https://www.hostingtg.com/blog/vulnerabilidad-en-acf-extended #acf #wordpress #seguridad

    Post summary

    The post announces a critical privilege‑escalation flaw in ACF Extended (CVE‑2025‑14533), detailing how front‑end form role mapping can grant admin rights.

    0000059
    976 followersView on X

Explore more