⤷ Title: Critical ACF Extended Flaw (CVE-2025-13486, CVSS 9.8) Allows Unauthenticated RCE on 100K WordPress Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 04:18:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ACF Extended #call_user_func_array #Critical Vulnerability #CVE_2025_13486 #rce #Unauthenticated Attack #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 04:18:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ACF Extended #call_user_func_array #Critical Vulnerability #CVE_2025_13486 #rce #Unauthenticated Attack #wordpress
Daily CyberSecurity
Critical ACF Extended Flaw (CVE-2025-13486, CVSS 9.8) Allows Unauthenticated RCE on 100K WordPress Sites
A Critical (CVSS 9.8) RCE flaw in ACF Extended allows unauthenticated attackers to run arbitrary code via the prepare_form function, risking 100K+ WordPress sites. Update to v0.9.2.