CVE-2012-10025

WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion

The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include and execute arbitrary remote PHP code. This leads to remote code execution under the web server’s context, allowing full compromise of the host.


We have discovered 318 live websites that are affected by CVE-2012-10025.

Run a Free Instant Scan




Affected Software

Product  Advanced Custom Fields
Category Wordpress Plugins
Vulnerable Domains318 live websites (3.61% of Advanced Custom Fields install base)
Vulnerable Versions
  • from 0 through 3.5.1
Vulnerable Versions Count2 versions ( 1.52% of all versions)


Common Weakness Enumeration

CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')



Details

  • Published - Aug 5, 2025
  • Updated - May 15, 2026

Credits

  • Charlie Eriksen (finder)

Website Distribution by Country

Number of websites using CVE-2012-10025
United States97 websites



Singapore45 websites
France32 websites
GB31 websites
Australia14 websites
Switzerland10 websites
Germany9 websites
Italy9 websites
Netherlands8 websites
Spain6 websites

Website Distribution by TLD

Number of websites using CVE-2012-10025
.com147 websites
.org29 websites
.co.uk15 websites
.com.au15 websites
.fr9 websites
.ch8 websites
.it5 websites
.org.uk5 websites
.com.br5 websites
.net4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2012-10025

Top websites that are affected by CVE-2012-10025. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.au Australia***,***
**************.net GB***,***
*********.com United States***,***
******.***.ph Philippines***,***
***.***.au United States***,***
******.***.au United States***,***
****.***.au United States***,***
**************.com United States***,***
************.com United States***,***
****.***.au United States***,***
See full domain list

FAQ

CVE-2012-10025 is Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in Advanced Custom Fields
A total of 318 websites have been identified as vulnerable to CVE-2012-10025, based on global website indexing conducted by WebTechSurvey.
The Advanced Custom Fields is affected by the CVE-2012-10025 vulnerability.
Advanced Custom Fields versions up to and including 3.5.1 are vulnerable to CVE-2012-10025.