The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Apr 2026 01:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-15T01:25:17.540Z
Reserved: 2026-03-25T13:02:36.082Z
Link: CVE-2026-4812
No data.
No data.
No data.
OpenCVE Enrichment
No data.