ACF On-The-Go
ACF On-The-Go has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for ACF On-The-Go has a vendor fix available, so running the current release closes it.
All of these findings were reported by Francesco Carlucci. ACF On-The-Go is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-3071ACF On-The-Go <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Update
Read the full analysisVulnerability Records

ACF On-The-Go
Author
Nadav Cohen
ACF On-The-Go lets site editors update Advanced Custom Fields (ACF) text and textarea field values right on the page where they appear, without opening WP-Admin. Edit your ACF text fields from the front-end of your website. Save time looking for the field in WP-Admin. See immediate results in the front-end. Changes are written straight to the database, so nothing is lost between the front-end edit and the admin view. Access is limited to logged-in users who can already edit the post being viewed. Developer & User friendly. IMPORTANT For fields to be editable on the front-end, YOU MUST ADD ‘acfgo’ to the target ACF field’s ‘Wrapper Attributes -> Class’ Right now the plugin only supports non-repeater text fields!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C