A critical privilege-escalation flaw, tracked as CVE-2025-14533, was disclosed in the WordPress plugin Advanced Custom Fields: Extended, enabling an unauthenticated attacker to register or modify a user account with the administrator role under certain configurations. The bug was traced to improper role restrictions in the plugin’s user creation and editing form handling, specifically the insert_user function, which could allow full compromise of a vulnerable WordPress instance.
The issue affects version 0.9.2.1 and earlier, and reporting indicated that roughly 100,000 WordPress sites were affected. Exploitation requires exposed Create User or Update User forms that make the role field available, increasing risk for sites using those features insecurely. The plugin maintainers released version 0.9.2.2 and later to fix the vulnerability, and defenders were urged to update immediately and review sites for unauthorized administrator accounts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The plugin developers released Advanced Custom Fields: Extended version 0.9.2.2 or later to fix CVE-2025-14533. The vulnerability affects version 0.9.2.1 and earlier.
A critical privilege-escalation vulnerability, tracked as CVE-2025-14533, was disclosed in the WordPress plugin Advanced Custom Fields: Extended. The flaw allows an unauthenticated attacker to assign themselves the administrator role during registration when vulnerable Create User or Update User forms expose the role field.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.