The ACF to REST API plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in all versions up to and including 3.3.4 due to insufficient authorization in the REST permission callback update_item_permissions_check(). The check only verifies the generic edit_posts capability and fails to enforce object-specific capability checks (e.g., edit_post($id), edit_user($id), manage_options). As a result, authenticated users with Contributor-level access or higher can use the /wp-json/acf/v3/{type}/{id} endpoints to modify ACF fields for objects they should not be able to edit, including posts they do not own, user accounts, comments, taxonomy terms, and the global options page.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a working exploit for CVE-2025-12030, an Insecure Direct Object Reference (IDOR) vulnerability in the ACF to REST API WordPress plugin (versions <= 3.3.4). The vulnerability allows authenticated users with Contributor-level access to modify Advanced Custom Fields (ACF) on any post, user, comment, taxonomy term, or global options, bypassing normal authorization checks. The repository contains: - `exploit.py`: A Python script that automates exploitation by authenticating to the target WordPress site (using Basic Auth with an application password), reading and modifying ACF fields via the vulnerable REST API endpoints. It supports targeting different object types and can confirm the vulnerability by modifying fields the user should not have access to. - `exploit.sh`: A Bash script alternative that uses curl and jq to perform the same exploit steps from the command line, supporting similar options and output formatting. - `CVE-2025-12030.yaml`: A Nuclei template for automated detection and exploitation of the vulnerability, specifying the required HTTP requests and matchers for successful exploitation. - `README.md`: A comprehensive documentation file detailing the vulnerability, its impact, exploitation steps, and references. The main attack vector is network-based, targeting the WordPress REST API endpoints under `/wp-json/acf/v3/`. The exploit requires valid Contributor-level credentials and an application password. The payload is a JSON object that sets arbitrary ACF fields on the targeted object. The repository is operational, providing both proof-of-concept and practical exploitation scripts.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.