CVE-2025-54940
Advanced Custom Fields <= 6.4.2. - HTML Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.
Existe una vulnerabilidad de inyección HTML en el complemento de WordPress "Advanced Custom Fields" anterior a la versión 6.4.3. Si se explota esta vulnerabilidad, se podría renderizar código HTML manipulado y alterar la visualización de la página.
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 6.4.2. This is due to the plugin nor properly neutralizing unsafe HTML. This makes it possible for authenticated attackers, with administrator-level access and above, to inject potentially malicious HTML.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-08-01 CVE Reserved
- 2025-08-08 CVE Published
- 2025-08-14 EPSS Updated
- 2025-08-25 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://jvn.jp/en/jp/JVN21048820 | ||
https://www.advancedcustomfields.com/blog/acf-6-4-3-security-release |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
WPEngine, Inc. Search vendor "WPEngine, Inc." | Advanced Custom Fields Search vendor "WPEngine, Inc." for product "Advanced Custom Fields" | 6.4.3 Search vendor "WPEngine, Inc." for product "Advanced Custom Fields" and version "6.4.3" | en |
Affected
|