CVE detail
CVE-2026-12428
The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic publish_posts capability and the handler passes a user-supplied id parameter directly to get_field_objects() without verifying that the requesting user is authorized to read the target object. This makes it possible for authenticated attackers, with Author-level access and above, to read ACF field values from arbitrary posts (including private posts, drafts, posts by other users, and other ACF-supported objects) that they should not have access to.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)Wordfence
.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13039 Patch Status Patched Published Jul 9, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Niv Kochan More Details > Extra Product Options Builder
vendorwww.wordfence.comJul 16, 2026, 8:29 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/fc48f75d-a2e8-49ea-9bfa-a27a61ff8a84?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 9, 2026, 11:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3587876%40acf-field-blocks&new=3587876%40acf-field-blocksplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 9, 2026, 11:16 AM - https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.6.0/inc/class-rest.php#L302plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 9, 2026, 11:16 AM - https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.6.0/inc/class-rest.php#L296plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 9, 2026, 11:16 AM - https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.6.0/inc/class-rest.php#L100plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 9, 2026, 11:16 AM - https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.5.0/inc/class-rest.php#L302plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 9, 2026, 11:16 AM - https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.5.0/inc/class-rest.php#L296plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 9, 2026, 11:16 AM - https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.5.0/inc/class-rest.php#L100plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 9, 2026, 11:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-72723CVSS 5.3 · Medium
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_menu_tags serializes tags from Si…
- CVE-2026-72722CVSS 4.3 · Medium
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_from, TopicLink.ensure_entry_for, and TopicLink.duplicate_l…
- CVE-2026-47754CVSS 9.3 · Critical
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path tra…
- CVE-2026-72759CVSS 6.9 · Medium
In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record references a deleted conversi…
- CVE-2026-71959CVSS 6.9 · Medium
Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to wri…
- CVE-2026-15060CVSS 4.7 · Medium
When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a deskto…