Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 21 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hwk-fr
Hwk-fr advanced Custom Fields Wordpress Wordpress wordpress |
|
| Vendors & Products |
Hwk-fr
Hwk-fr advanced Custom Fields Wordpress Wordpress wordpress |
Tue, 20 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can only be exploited if 'role' is mapped to the custom field. | |
| Title | Advanced Custom Fields: Extended <= 0.9.2.1 - Unauthenticated Privilege Escalation via Insert User Form Action | |
| Weaknesses | CWE-269 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:25:47.419Z
Reserved: 2025-12-11T10:11:32.336Z
Link: CVE-2025-14533
Updated: 2026-01-20T15:09:17.443Z
Status : Deferred
Published: 2026-01-20T10:16:05.583
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-14533
No data.
OpenCVE Enrichment
Updated: 2026-04-20T21:15:20Z