CVE-2023-1196: Advancedcustomfields Advanced Custom Fields

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present.

Affected products

  • Advancedcustomfields Advanced Custom Fields: from 5.0.0, before 5.12.5 (fixed in 5.12.5); from 6.0.0, before 6.1.0 (fixed in 6.1.0)

Published 2023-05-02. Last modified 2026-06-17.