50,000 WordPress site affected in major plugin security flaw – here’s how to stay safe



  • Critical bug in ACF: Extended WordPress plugin allows arbitrary role escalation to administrator
  • About 50,000 WordPress sites are vulnerable despite patch in version 0.9.2.2
  • No exploitation reported yet, but attackers likely to probe exposed sites soon

Around 50,000 WordPress websites are currently at risk of full site takeover, due to a critical-severity vulnerability that was recently discovered in a popular plugin.

In mid-December 2025, Wordfence was notified by security researcher Andrea Bocchetti of a vulnerability in Advanced Custom Fields: Extended, a plugin which adds more features to the Advanced Custom Fields (ACF) plugin.


https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img