Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… Security & Risk Analysis

wordpress.org/plugins/acf-views

Display content with full control over selection and layout. Lightweight and compatible with any theme or page builder.

2K active installs v3.8.3 PHP 7.4+ WP 5.5+ Updated Feb 27, 2026
custom-post-typesmeta-fieldspost-gridtaxonomywp_query
98
A · Safe
CVEs total1
Unpatched0
Last CVESep 22, 2025
Safety Verdict

Is Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… Safe to Use in 2026?

Generally Safe

Score 98/100

Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 22, 2025Updated 1mo ago
Risk Assessment

The 'acf-views' plugin version 3.8.3 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The absence of dangerous functions and critical/high severity taint flows is also a significant strength, indicating a generally well-written codebase.

However, notable concerns arise from the plugin's attack surface. Specifically, one AJAX handler lacks authentication checks, presenting a potential entry point for unauthorized actions. While there are no active unpatched CVEs, the presence of one past high-severity vulnerability, categorized as 'Improper Neutralization of Special Elements Used in a Template Engine', suggests that the plugin has historically been susceptible to complex injection attacks. This history, combined with the unprotected AJAX handler, warrants careful consideration.

In conclusion, while 'acf-views' v3.8.3 shows commendable security development practices in areas like SQL and output handling, the unprotected AJAX endpoint and the history of a high-severity template engine vulnerability are weaknesses that could be exploited. Vigilance is recommended, especially regarding the uncovered AJAX endpoint.

Key Concerns

  • Unprotected AJAX handler
  • Past high severity vulnerability
Vulnerabilities
1

Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-10380high · 8.8Improper Neutralization of Special Elements Used in a Template Engine

Advanced Views – Display Posts, Custom Fields, and More <= 3.7.19 - Authenticated (Author+) Remote Code Execution via SSTI

Sep 22, 2025 Patched in 3.7.20 (1d)
Code Analysis
Analyzed Mar 16, 2026

Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
42
410 escaped
Nonce Checks
2
Capability Checks
1
File Operations
12
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared14 total queries

Output Escaping

91% escaped452 total outputs
Attack Surface
1 unprotected

Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_acf/fields/av_slug_select/querysrc\Groups_Integration\Av_Slug_Select_Field.php:51

REST API Routes 1

POST/wp-json/acf_views/v1/live-reloadersrc\Dashboard\Live_Reloader.php:467
WordPress Hooks 4
actioninitsrc\Plugin\Plugin_Loader_Base.php:203
actionacf/initsrc\Plugin\Plugin_Loader_Base.php:246
actioninitsrc\Plugin.php:183
actionshutdownsrc\Utils\Profiler.php:39
Maintenance & Trust

Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 27, 2026
PHP min version7.4
Downloads103K

Community Trust

Rating96/100
Number of ratings35
Active installs2K
Developer Profile

Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… Developer Profile

WPLake

1 plugin · 2K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acf-views/src/assets/css/admin.css/wp-content/plugins/acf-views/src/assets/css/admin-layout-edit.css/wp-content/plugins/acf-views/src/assets/css/layout-select.css/wp-content/plugins/acf-views/src/assets/css/layout-view.css/wp-content/plugins/acf-views/src/assets/css/post-selection-edit.css/wp-content/plugins/acf-views/src/assets/css/post-selection-view.css/wp-content/plugins/acf-views/src/assets/css/views.css/wp-content/plugins/acf-views/src/assets/js/admin.js+6 more
Script Paths
/wp-content/plugins/acf-views/src/assets/js/admin.js/wp-content/plugins/acf-views/src/assets/js/admin-layout-edit.js/wp-content/plugins/acf-views/src/assets/js/admin-post-selection-edit.js/wp-content/plugins/acf-views/src/assets/js/layout-select.js/wp-content/plugins/acf-views/src/assets/js/live-reloader.js/wp-content/plugins/acf-views/src/assets/js/post-selection-select.js+1 more
Version Parameters
/wp-content/plugins/acf-views/src/assets/css/admin.css?ver=/wp-content/plugins/acf-views/src/assets/css/admin-layout-edit.css?ver=/wp-content/plugins/acf-views/src/assets/css/layout-select.css?ver=/wp-content/plugins/acf-views/src/assets/css/layout-view.css?ver=/wp-content/plugins/acf-views/src/assets/css/post-selection-edit.css?ver=/wp-content/plugins/acf-views/src/assets/css/post-selection-view.css?ver=/wp-content/plugins/acf-views/src/assets/css/views.css?ver=/wp-content/plugins/acf-views/src/assets/js/admin.js?ver=/wp-content/plugins/acf-views/src/assets/js/admin-layout-edit.js?ver=/wp-content/plugins/acf-views/src/assets/js/admin-post-selection-edit.js?ver=/wp-content/plugins/acf-views/src/assets/js/layout-select.js?ver=/wp-content/plugins/acf-views/src/assets/js/live-reloader.js?ver=/wp-content/plugins/acf-views/src/assets/js/post-selection-select.js?ver=/wp-content/plugins/acf-views/src/assets/js/views.js?ver=

HTML / DOM Fingerprints

CSS Classes
acf-views-admin-layout-editacf-views-admin-post-selection-editacf-views-layout-selectacf-views-layout-viewacf-views-post-selection-editacf-views-post-selection-viewacf-views-field-wrapperacf-views-layout-wrapper+1 more
HTML Comments
<!-- ACF Views --><!-- ACF Views Layout --><!-- ACF Views Post Selection -->
Data Attributes
data-acf-views-layout-iddata-acf-views-post-selection-iddata-acf-views-live-reloader
JS Globals
acf_views_admin_layout_editacf_views_admin_post_selection_editacf_views_layout_selectacf_views_live_reloaderacf_views_post_selection_select
REST Endpoints
/wp-json/acf-views/v1/layouts/wp-json/acf-views/v1/post-selections
Shortcode Output
[acf_views_layout][acf_views_post_selection]
FAQ

Frequently Asked Questions about Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…