PricingCase studies Login Start trial
Plugin Icon

Advanced Custom Fields PRO

N/A

Developer

N/A

Latest version

N/A

Installations

N/A

Last updated

WordPress Plugin
No VDP
Claim ownership
Report vulnerability
    VulnerabilitiesSecurity Contributors

Vulnerability history

0 present
17 fixed
5 Mitigation rules
  • Authenticated (Admin+) Stored Cross-Site Scripting vulnerability
    <= 6.3.8
    Oct 16, 2024
  • Administrator+ Limited Arbitrary Function Call vulnerability
    <= 6.3.7
    Oct 9, 2024
  • Missing Authorization to Information Disclosure vulnerability
    < 5.11
    Oct 4, 2024
  • Missing Authorization to Information Disclosure vulnerability
    < 5.11
    Oct 4, 2024
  • Missing Authorization on Option Changes vulnerability
    < 5.11
    Oct 4, 2024
  • Cross-Site Request Forgery (CSRF) vulnerability
    < 6.3.2
    Jun 26, 2024
  • Subscriber+ Broken Access Control vulnerability
    < 6.3.2
    Jun 26, 2024
  • Contributor+ Broken Access Control vulnerability
    < 6.3.2
    Jun 26, 2024
  • Auth. Custom Field Access vulnerability
    < 6.3
    Jun 3, 2024
  • Contributor+ Local File Inclusion vulnerability
    < 6.2.10
    May 15, 2024
  • Contributor+ Arbitrary Function Execution vulnerability
    < 6.2.10
    May 15, 2024
  • Contributor+ Stored Cross-Site Scripting vulnerability
    < 6.2.5
    Jan 16, 2024
  • Auth. Stored Cross-Site Scripting (XSS) vulnerability
    6.1-6.1.7
    Aug 10, 2023
  • Reflected Cross Site Scripting (XSS) vulnerability
    <= 6.1.5
    May 5, 2023
  • Contributor+ PHP Object Injection vulnerability
    < 6.1.0
    May 2, 2023
  • Unauthenticated File Upload vulnerability
    <= 5.12.2
    Aug 1, 2022
  • Reflected Cross-Site Scripting (XSS) vulnerability
    <= 5.9.0
    Apr 2, 2021

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Documentation
  • Service status
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory 1,085
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag