ACF: Better Search
ACF: Better Search has one disclosed vulnerability in the WordSec catalog, all reported in 2019; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for ACF: Better Search has a vendor fix available, so running the current release closes it.
ACF: Better Search is installed on roughly 40,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2019-14682ACF Better Search <= 3.3.0 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

ACF: Better Search
Author
Mateusz Gbiorczyk
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin. Everything works automatically, no need to add any additional code. The plugin does not create a search results page, but modifies the SQL database query to make your search engine work better. Additionally you can search for whole phrases instead of each single word of phrase. As a result, search will be more accurate than before. New search core We modified the code of search engine. Content search is now faster by about 75% (depending on the level of complexity of searched phrase)! Support to the development of plugin We spend hours working on the development of this plugin. Technical support also requires a lot of time, but we do it because we want to offer you the best plugin. We enjoy every new plugin installation. If you would like to appreciate it, you can provide us a coffee. If every user bought at least one, we could work on the plugin 24 hours a day! Please also read the FAQ below. Thank you for being with us!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C