50,000 WordPress Sites Affected by Serious Plugin Security Flaw – Here’s How to Protect Yourself


  • Critical bug in ACF: Advanced WordPress plugin allows admin to arbitrarily promote roles
  • Nearly 50,000 WordPress sites vulnerable despite patch in version 0.9.2.2
  • No exploits have been reported yet, but attackers are likely to explore the exposed sites soon

About 50,000 WordPress websites are currently at risk of being completely taken over by a newly discovered critical vulnerability in a popular plugin.

In mid-December 2025, security researcher Andrea Bocchetti reported to Wordfence a vulnerability in Advanced Custom Fields – Extended, a plugin that adds more functionality to the Advanced Custom Fields (ACF) plugin.

Leave a Reply

Your email address will not be published. Required fields are marked *