High severity8.8NVD Advisory· Published Aug 22, 2022· Updated Jun 17, 2026
CVE-2022-2594
CVE-2022-2594
Description
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:*:wordpress:*:*range: >=5.0.0,<5.12.3
- cpe:2.3:a:advancedcustomfields:advanced_custom_fields:*:*:*:*:pro:wordpress:*:*range: >=5.0.0,<5.12.3
- Range: <5.12.3
- Range: <5.12.3
- TODO/Advanced Custom Fieldsv5Range: 5.0
- TODO/Advanced Custom Fields Prov5Range: 5.0
Patches
Vulnerability mechanics
References
2- wpscan.com/vulnerability/3fde5336-552c-4861-8b4d-89a16735c0e2nvdExploitThird Party Advisory
- www.pritect.net/blog/advanced-custom-fields-5-12-3-can-allow-unauthenticated-users-to-upload-arbitrary-filesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.