WordPress plugin vulnerability puts two million websites at risk

A popular WordPress plugin could be putting around two million websites at risk of attack.

According to security researchers, two million WordPress websites could be at risk of attack due to a vulnerability found in a popular WordPress plugin. The plugin in question is the Advanced Custom Fields and Advanced Custom Fields Pro plugins, which have been found to be vulnerable to cross-site scripting (XSS) attacks. This vulnerability is considered to be of high severity and could allow a malicious hacker to inject harmful scripts into a website. These scripts could include redirects, adverts, and other HTML content, which would execute when users visited the targeted website.

The good news is that the vulnerability can only be exploited by logged-in users who have access to the vulnerable plugin. This means that non-logged-in attackers would have to trick someone with the appropriate privileges to visit a malicious URL to trigger an attack. However, it is still important that affected sites are patched promptly to ensure they are protected.

Security researcher Rafie Muhammad discovered the XSS vulnerability three days ago, and plugin developer WPEngine released a patch yesterday. Administrators of WordPress websites using the affected plugins should update Advanced Custom Fields to version 6.1.6 or later to prevent potential attacks.

As a precautionary measure, website administrators are advised to patch the plugin as soon as possible. This is particularly important as the vulnerability has not yet been exploited, although there is always a possibility that it could be. In fact, Graham Cluley, an IT and security expert who runs a website using the plugin, has already taken steps to update his site’s plugin to the latest version.

Fortunately, updating the plugin is a straightforward process that can be done via the WordPress admin console. It is also advisable to enable automatic updates for plugins to ensure that they are always up to date with the latest security patches.

Ahsan Sher

It is an honor to be part of the AlifBey Team. Well I'm mainly interested in programming but I'll bring you articles you may have never read before, especially computer tactics when you need them and for you. Also surprising ... If you think I need correction, please correct me.

Adobe Photoshop Is Now Built Into ChatGPT for Free — No Design Skills Needed

Adobe has officially changed the creative game. Adobe Photoshop is now built directly into ChatGPT…

18 hours

Introducing GPT 5.2 The Most Advanced AI Model for Professional Work

Artificial intelligence is moving faster than ever and OpenAI has once again raised the bar…

2 days

The New SEO Revolution Why Search Everywhere Optimization Is Winning Now

SEO is not dead but it has evolved far beyond keywords and backlinks. If you…

1 week

5 Nutrients That Make Oranges So Good for You

Oranges are more than a refreshing citrus snack. Whether it is navel oranges blood oranges…

1 week

SEO Limits You Must Follow in 2026: The Ultimate Guide

Understanding the right SEO limits in 2026 can decide whether your content reaches page one…

2 weeks

How Much RAM Does Your PC Actually Need in 2026? A Practical Guide for Windows, Mac & Chromebook Users

If your computer feels sluggish, you’re likely trying to figure out the same question thousands…

2 weeks