CVE-2026-12526
Received Received - Intake

Unauthenticated Password Change in ACF Extended WordPress Plugin

Vulnerability report for CVE-2026-12526, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a publicly reachable front-end form whose user-update action targets an existing administrator (a fixed target, or one mapped to a visitor-submitted field) and maps the password to a visitor-submitted field, an unauthenticated visitor can overwrite that administrator's password and take over the account. The default target is the submitting user, so exploitation depends on the form being configured to target another account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
advanced_custom_fields extended_wordpress_plugin to 0.9.2.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Advanced Custom Fields: Extended WordPress plugin before version 0.9.2.7. It allows unauthenticated visitors to take over an administrator account by exploiting the front-end user update feature. The plugin fails to verify proper authorization when editing user accounts through the update-user action in its Forms module. It only checks capabilities if the submitted role is administrator or super_admin.

Detection Guidance

Check if you are running Advanced Custom Fields: Extended WordPress plugin version prior to 0.9.2.7. Inspect front-end forms for user-update actions targeting administrator accounts with password fields mapped to visitor input. Look for unauthorized password changes in admin accounts.

Impact Analysis

An attacker could gain full control of an administrator account, allowing them to modify site content, install malicious plugins, or steal sensitive data. This could lead to complete site compromise, data breaches, or defacement. The impact depends on whether the site uses a vulnerable form configuration targeting an administrator.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access controls. A successful exploit may result in data breaches, triggering mandatory breach notifications and potential fines under these regulations.

Mitigation Strategies

Update the Advanced Custom Fields: Extended WordPress plugin to version 0.9.2.7 or later immediately. Disable any publicly accessible front-end forms that allow user account updates targeting administrator accounts. Review and restrict form configurations to prevent unauthorized account modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12526. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart