peter bassill · operator
$ cve CVE-2025-13486 JSON

CVE-2025-13486

9.8
CRITICAL · CVSS 3.1 · EPSS 67.6% (pctl 99)

Patch early

EPSS 67.6% — above the 10% action threshold.

Description

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS67.62% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploitnone known
Published2025-12-03
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD