CVE-2025-14533 Vulnerability Gives Admin Access to 50,000 WordPress Sites
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The Advanced Custom Fields: Extended (ACF Extended) plugin for WordPress has a critical-severity vulnerability, identified as CVE-2025-14533, that enables unauthenticated attackers to gain administrative access. This vulnerability affects approximately 50,000 websites that have not updated to version 0.9.2.2, which was released on December 14, 2025, just days after the issue was reported by security researcher Andrea Bocchetti.
The flaw arises from a lack of enforcement of role restrictions during user creation or updates via the plugin’s ‘Insert User / Update User’ form action. Even if role limitations are configured, attackers can exploit this vulnerability to set a user’s role to ‘administrator’ without restrictions, leading to complete site compromise.
While no active attacks exploiting CVE-2025-14533 have been reported, threat monitoring firm GreyNoise has observed significant reconnaissance activity targeting WordPress plugins. From late October 2025 to mid-January 2026, nearly 1,000 IPs targeted 706 distinct plugins in over 40,000 enumeration events.
Among the most targeted plugins are Post SMTP, Loginizer, LiteSpeed Cache, SEO by Rank Math, Elementor, and Duplicator. This reconnaissance suggests that attackers are actively searching for vulnerabilities to exploit, raising concerns for site administrators.
Wordfence has warned that the vulnerability can be exploited on sites using a ‘Create User’ or ‘Update User’ form with a role field mapped. This highlights the importance of monitoring plugin usage and ensuring timely updates to mitigate risks.
Understanding the Risks
For everyday users and organizations, the implications of this vulnerability are significant. If a site is compromised, attackers can gain full control, potentially leading to data breaches, loss of sensitive information, and damage to the site’s reputation.
Site administrators should be vigilant about monitoring their plugins and ensuring they are running the latest versions. Regularly checking for updates and understanding the specific functionalities of plugins can help mitigate risks associated with vulnerabilities like CVE-2025-14533.
As the landscape of cyber threats continues to evolve, staying informed about vulnerabilities and implementing best practices in plugin management is crucial for maintaining security.
Key Takeaways
- Update the ACF Extended plugin to version 0.9.2.2 or later to close the vulnerability.
- Regularly monitor your WordPress plugins for updates and security patches.
- Review user roles and permissions to ensure they are configured correctly and restrict unauthorized access.
- Implement security measures such as firewalls and monitoring tools to detect unusual activity on your site.
- Stay informed about emerging vulnerabilities and threats affecting WordPress plugins.
Key Terms & Concepts
- CVE-2025-14533: In this article, CVE-2025-14533 refers to a critical vulnerability in the ACF Extended plugin that allows unauthorized admin access.
- Advanced Custom Fields: Extended (ACF Extended): ACF Extended is a WordPress plugin that enhances the functionality of the Advanced Custom Fields plugin for developers.
- Wordfence: Wordfence is a security plugin for WordPress that helps protect websites from vulnerabilities and attacks.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.