
CVE-2026-4812 The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. Th… https://www.cve.org/CVERecord?id=CVE-2026-4812
Post summary
A new CVE (CVE-2026-4812) affecting Advanced Custom Fields plugin is disclosed, describing missing authorization that allows arbitrary post/page disclosure; no patch, PoC, or exploitation evidence is provided.
