CVE-2026-8382

Advanced Custom Fields (ACF®) <= 6.8.1 - Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and post_content of any post bound to a publicly accessible acf_form() instance by injecting values into the _post_title and _post_content parameters of a form submission request.


We have discovered 6,423 live websites that are affected by CVE-2026-8382.

Run a Free Instant Scan




Affected Software

Product  Advanced Custom Fields
Category Wordpress Plugins
Vulnerable Domains6,423 live websites (73% of Advanced Custom Fields install base)
Vulnerable Versions
  • from 0 through 6.8.1
Vulnerable Versions Count124 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - May 31, 2026
  • Updated - Jun 1, 2026

Credits

  • Sarawut Poolkhet (finder)

Website Distribution by Country

Number of websites using CVE-2026-8382
United States1,938 websites



France600 websites
Germany496 websites
GB490 websites
Russia246 websites
Canada226 websites
Netherlands203 websites
Italy169 websites
Spain163 websites
Switzerland145 websites

Website Distribution by TLD

Number of websites using CVE-2026-8382
.com2,440 websites
.org424 websites
.fr352 websites
.de292 websites
.co.uk274 websites
.ru184 websites
.nl179 websites
.it118 websites
.com.au117 websites
.net113 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-8382

Top websites that are affected by CVE-2026-8382. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States*,***
*********.com United States*,***
******************.org United States**,***
**************.com United States**,***
************.com United States**,***
********.com United States**,***
*****.com United States**,***
************.org United States**,***
****.org United States**,***
****.org United States**,***
See full domain list

FAQ

CVE-2026-8382 is Missing Authorization in Advanced Custom Fields
A total of 6,423 websites have been identified as vulnerable to CVE-2026-8382, based on global website indexing conducted by WebTechSurvey.
The Advanced Custom Fields is affected by the CVE-2026-8382 vulnerability.
Advanced Custom Fields versions up to and including 6.8.1 are vulnerable to CVE-2026-8382.