The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and post_content of any post bound to a publicly accessible acf_form() instance by injecting values into the _post_title and _post_content parameters of a form submission request.
We have discovered 6,423 live websites that are affected by CVE-2026-8382.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 6,423 live websites (73% of Advanced Custom Fields install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 124 versions ( 94% of all versions) |
| 1,938 websites | |
| 600 websites | |
| 496 websites | |
| 490 websites | |
| 246 websites | |
| 226 websites | |
| 203 websites | |
| 169 websites | |
| 163 websites | |
| 145 websites |
| .com | 2,440 websites |
| .org | 424 websites |
| .fr | 352 websites |
| .de | 292 websites |
| .co.uk | 274 websites |
| .ru | 184 websites |
| .nl | 179 websites |
| .it | 118 websites |
| .com.au | 117 websites |
| .net | 113 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | *,*** | ||
| *********.com | *,*** | ||
| ******************.org | **,*** | ||
| **************.com | **,*** | ||
| ************.com | **,*** | ||
| ********.com | **,*** | ||
| *****.com | **,*** | ||
| ************.org | **,*** | ||
| ****.org | **,*** | ||
| ****.org | **,*** |
FAQ