CVE-2012-10025
The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include and execute arbitrary remote PHP code. This leads to remote code execution under the web server’s context, allowing full compromise of the host.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 45.98%
- CWE
- CWE-98
- Published
- 2025-08-05
- Last modified
- 2026-05-15
Affected products
- Advanced Custom Fields WordPress Plugin
- Advanced Custom Fields WordPress Plugin
Weakness type
Related vulnerabilities
- CVE-2026-41228 — Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution
- CVE-2026-9559 — A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files dur
- CVE-2026-11613 — Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter
- CVE-2026-7515 — BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
- CVE-2026-66587 — WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability
- CVE-2026-8134 — Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion
- CVE-2026-8208 — Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the re
- CVE-2026-44177 — Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup