CVE-2025-13486
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
- Affected products
- Advanced Custom Fields: Extended
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 67.6% (99th percentile)
- Weakness
- CWE-94
- NVD status
- Deferred
- Published
- 2025-12-03
CVE-2025-13486 at NVD
18 known exploits for CVE-2025-13486
Proof-of-concept code and exploit modules indexed by Sploitus
cms-exploitation-campaign
CVE-2025-13486.-CVE-2025-13486
CVE-2025-13486-POC
CVE-2025-13486
CVE-2025-13486
cve-2025-13486-vuln-setup
CVE-2025-13486
Ntemplatesbyxit
π WordPress ACF 0.9.1.1 Remote Code Execution
Exploit for CVE-2025-13486
Exploit for CVE-2025-13486
π WordPress ACF 0.9.1.1 Remote Code Execution
Exploit for CVE-2025-13486
Exploit for CVE-2025-13486
Exploit for CVE-2025-13486
Exploit for CVE-2025-13486
Exploit for CVE-2025-13486
WordPress ACF Extended Unauthenticated RCE via prepare_form()