Critical ACF Extended Flaw (CVE-2025-13486, CVSS 9.8) Allows Unauthenticated RCE on 100K WordPress Sites Vulnerability Report Critical ACF Extended Flaw (CVE-2025-13486, CVSS 9.8) Allows Unauthenticated RCE on 100K WordPress Sites Do Son December 3, 2025 0 A critical security vulnerability carrying a near-maximum severity score has been discovered in “Advanced Custom Fields: Extended,”... Read More Read more about Critical ACF Extended Flaw (CVE-2025-13486, CVSS 9.8) Allows Unauthenticated RCE on 100K WordPress Sites