CVE-2025-14983

Publication date

2026-02-19 04:36:22

Family

Wordfence

State

PUBLISHED

Description

The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible forauthenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts that execute in a victims browser.