50,000 WordPress site affected in major plugin security flaw – here’s how to stay safe

50,000 WordPress site affected in major plugin security flaw – here’s how to stay safe


  • Critical bug in ACF: Extended WordPress plugin allows arbitrary role escalation to administrator
  • About 50,000 WordPress sites are vulnerable despite patch in version 0.9.2.2
  • No exploitation reported yet, but attackers likely to probe exposed sites soon

Around 50,000 WordPress websites are currently at risk of full site takeover, due to a critical-severity vulnerability that was recently discovered in a popular plugin.

In mid-December 2025, Wordfence was notified by security researcher Andrea Bocchetti of a vulnerability in Advanced Custom Fields: Extended, a plugin which adds more features to the Advanced Custom Fields (ACF) plugin.


link

Leave a Reply

Your email address will not be published. Required fields are marked *