Advanced Custom Fields : CPT Options Pages
Advanced Custom Fields : CPT Options Pages has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Advanced Custom Fields : CPT Options Pages has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Najib Sinjari. Advanced Custom Fields : CPT Options Pages is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.
CVE-2025-60208Advanced Custom Fields : CPT Options Pages <= 2.0.9 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Advanced Custom Fields : CPT Options Pages
Author
Tusko Trush
Small addon for ACF Options. Adds ACF location for each custom post type. New feature in the major version 2! Important! After update to v2+ you must reconnect Field Groups to Options Pages Now you can activate/deactivate CPTs and create custom options pages for each CPT. By default, options pages are activated for all custom post types. Usage The default functions of ACF plugin (get_field, the_field, etc.) can be used to load values from a CPT Options Pages, but second parameter is required to target the CPT options. This is similar to passing through a $post_id parameter to target a specific post object. The $post_id parameter needed is a string containing the cpt_ and CPT name in the following format; "cpt_{CPT_NAME}" and for subpages you can copy generated ID while creating subpages. Examples In examples Custom Post Type name is projects. So, let’s go! Display a field <p><?php the_field('field_name', 'cpt_projects'); ?></p> and the subpage’s field <p><?php the_field('field_name', 'cpt_projects_testpage'); ?></p> Retrieve a field <?php $field = get_field('field_name', 'cpt_projects'); // do something with $field ?> Display a sub field <?php if( have_rows('repeater_name', 'cpt_projects') ): ?> <ul> <?php while( have_rows('repeater_name', 'cpt_projects') ): the_row(); ?> <li><?php the_sub_field('the_title'); ?></li> <?php endwhile; ?> </ul> <?php endif; ?> Display with shortcode [acf field="field_name" post_id="cpt_projects"] Please read documentation about shortcodes with ACF Customization function cpt_projects_customize($cptmenu) { $cptmenu['page_title'] = 'Dev Custom title'; $cptmenu['menu_title'] = 'Dev Custom title'; return $cptmenu; } add_filter('cpt_projects_acf_page_args', 'cpt_projects_customize'); Don’t forget to replace cpt_projects_ to your custom post type name 🙂 It works only for first level options pages, not for subpages. Donate Support plugin License Copyright (c) 2023, Tusko Trush Requirements You must buy ACF PRO or ACF Options Page Addon. Translation qTranslate-XT This plugin is compatible and has included ACF qTranslate. Just enjoy! qTranslate-X If you are using Qtranslate-X, you must install ACF qTranslate. WPML/Polylang If you are using WPML or Polylang, you must add constant ICL_LANGUAGE_CODE to post_id, for example: get_field('archive_title', 'cpt_projects_' . ICL_LANGUAGE_CODE).
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C