CVE-2012-10025
Advanced Custom Fields <= 3.5.1 - Remote Code Execution via Remote File Inclusion
lowImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
3.8
CVSS Score
3.8
CVSS Score
low
Severity
3.5.2
Patched in
4615d
Time to patch
Description
Advanced Custom Fields up to 3.5.1 is vulnerable to Remote Code Execution. The vulnerability allows for remote file inclusion and remote code execution via the export.php script. This exploit only works when the php option allow_url_include is set to On (Default Off).
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Low
Confidentiality
Low
Integrity
None
Availability
Technical Details
Affected versions
<=3.5.1PublishedJanuary 3, 2013
Last updatedAugust 22, 2025
Affected pluginadvanced-custom-fields
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.