Critical WordPress Flaw in ACF Extended Grants Hackers Instant Admin Rights
A critical vulnerability (CVE-2025-14533) in the ACF Extended WordPress plugin allows unauthenticated attackers to gain administrative privileges via user creation forms. Users must update to version 0.9.2.2 immediately to prevent complete site compromise.
Tappy Admin
3 min read
Jan 25, 2026
129 views
#ACF Extended vulnerability
#CVE-2025-14533
#WordPress security
#ACF Extended exploit
#privilege escalation
#WordPress plugin patch
#admin takeover
#Wordfence alert
#critical security flaw
#cybersecurity news
Read More