CVE-2023-1196
About
The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present.
Rainforest analyst review
The Advanced Custom Fields plugin, in the 5.x and 6.x ranges before 5.12.5 and 6.1.0, unserializes user-controllable data, opening the door to PHP Object Injection. The two stated preconditions matter: the attacker needs at least a Contributor-level account, and a suitable gadget chain has to exist in the loaded code for the injection to escalate into something dangerous like code execution. Absent a gadget, the object injection is inert.
ACF is one of the most widely installed WordPress plugins, which is why this gets attention, but the exploitation reality is gated harder than the 8.8 suggests. It requires an authenticated contributor, not an anonymous request, and its severity depends on other plugins or themes supplying a usable gadget, so it is more a component of a chain than a standalone mass-exploit. Sites that hand out contributor accounts freely are the ones genuinely exposed.
We would rank this by the intersection of preconditions rather than the headline score: which of our WordPress sites run a vulnerable ACF version, allow untrusted contributor registrations, and carry a plausible gadget source. Given how hard plugins are to inventory per-site, our first task is enumerating ACF versions across the estate; the sites that also have open low-tier registration rise to the top, the rest can follow the normal patch cycle.
References
Related CVEs
Frequently asked questions
What is CVE-2023-1196?
The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present.
How severe is CVE-2023-1196?
CVE-2023-1196 carries a CVSS 3.1 base score of 8.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 89 out of 100, in the critical band.
How is CVE-2023-1196 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2023-1196?
Public advisories list the following as affected: advanced custom fields. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-1196?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
