The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper authorization checks. This makes it possible for unauthenticated attackers with access to a frontend ACF form to enumerate and disclose information about draft/private posts, restricted post types, and other data that should be restricted by field configuration.
We have discovered 5,195 live websites that are affected by CVE-2026-4812.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 5,195 live websites (59% of Advanced Custom Fields install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 120 versions ( 91% of all versions) |
| 1,501 websites | |
| 510 websites | |
| 407 websites | |
| 390 websites | |
| 239 websites | |
| 153 websites | |
| 148 websites | |
| 148 websites | |
| 119 websites | |
| 116 websites |
| .com | 1,920 websites |
| .org | 356 websites |
| .fr | 292 websites |
| .de | 238 websites |
| .co.uk | 213 websites |
| .ru | 178 websites |
| .nl | 135 websites |
| .it | 106 websites |
| .com.br | 97 websites |
| .net | 95 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | *,*** | ||
| *********.com | *,*** | ||
| ******************.org | **,*** | ||
| **************.com | **,*** | ||
| ********.com | **,*** | ||
| *****.com | **,*** | ||
| ************.org | **,*** | ||
| ****.org | **,*** | ||
| *************.com | **,*** | ||
| ************.pt | **,*** |
FAQ