The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include and execute arbitrary remote PHP code. This leads to remote code execution under the web server’s context, allowing full compromise of the host.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Advanced Custom Fields
Advanced Custom Fields advanced Custom Fields Wordpress Plugin Wordpress Wordpress wordpress |
|
Vendors & Products |
Advanced Custom Fields
Advanced Custom Fields advanced Custom Fields Wordpress Plugin Wordpress Wordpress wordpress |
Tue, 05 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include and execute arbitrary remote PHP code. This leads to remote code execution under the web server’s context, allowing full compromise of the host. | |
Title | WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion | |
Weaknesses | CWE-98 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-05T20:06:00.838Z
Updated: 2025-08-05T20:06:00.838Z
Reserved: 2025-08-05T15:43:27.678Z
Link: CVE-2012-10025

No data.

Status : Awaiting Analysis
Published: 2025-08-05T20:15:33.193
Modified: 2025-08-05T21:06:02.657
Link: CVE-2012-10025

No data.