50,000 WordPress Sites Affected by Major Plugin Security Flaw – Here’s How to Stay Safe


  • Critical bug in ACF: Extended WordPress plugin allows arbitrary role escalation to admin
  • About 50,000 WordPress sites are vulnerable despite patch in version 0.9.2.2
  • No exploits have been reported yet, but attackers are likely to investigate vulnerable sites soon

About 50,000 WordPress sites are currently at risk of a site-wide takeover due to a critical vulnerability recently discovered in a popular plugin.

In mid-December 2025, Wordfence was notified by security researcher Andrea Bocchetti of a vulnerability in Advanced Custom Fields: Extended, a plugin that adds more features to the Advanced Custom Fields (ACF) plugin.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top