CVE-2025-54940

LOW

WordPress Advanced Custom Fields <6.4.3 - XSS

Title source: llm
STIX 2.1

Description

An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.

References (2)

Core 2

Scores

CVSS v3 3.4
EPSS 0.0019
EPSS Percentile 9.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (1)
WPEngine, Inc./Advanced Custom Fields prior to 6.4.3
Published Aug 08, 2025
Tracked Since Feb 18, 2026