Title: Patchstack vulnerability
Last modified: August 6, 2026

---

# Patchstack vulnerability

 *  [Sebastien SERRE](https://wordpress.org/support/users/sebastienserre/)
 * (@sebastienserre)
 * [2 weeks, 1 day ago](https://wordpress.org/support/topic/patchstack-vulnerability-3/)
 * Hello,
   Patchstack is reporting a security issue: [https://patchstack.com/database/wordpress/plugin/advanced-custom-fields-font-awesome/vulnerability/wordpress-advanced-custom-fields-font-awesome-field-plugin-6-1-1-broken-access-control-vulnerability?_a_id=454](https://patchstack.com/database/wordpress/plugin/advanced-custom-fields-font-awesome/vulnerability/wordpress-advanced-custom-fields-font-awesome-field-plugin-6-1-1-broken-access-control-vulnerability?_a_id=454)
   Do you plan an update ?
 * Thank you

Viewing 6 replies - 1 through 6 (of 6 total)

 *  Plugin Author [Justin Kruit](https://wordpress.org/support/users/justinkruit/)
 * (@justinkruit)
 * [2 weeks, 1 day ago](https://wordpress.org/support/topic/patchstack-vulnerability-3/#post-18986120)
 * I’ve received a mail about Patchstack when they originally reported it. However,
   their site broke when I tried to see the details of the report so I never got
   around to looking at it. I’ll be giving it another try this weekend.
 *  [charactercreates](https://wordpress.org/support/users/charactercreates/)
 * (@charactercreates)
 * [2 weeks, 1 day ago](https://wordpress.org/support/topic/patchstack-vulnerability-3/#post-18986619)
 * Hi, I too have picked up a vulnerability in my latest scan on one of my sites.
 * WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 – Broken
   Access Control vulnerability
 * Will a fix be updated soon?
 *  Plugin Author [Justin Kruit](https://wordpress.org/support/users/justinkruit/)
 * (@justinkruit)
 * [2 weeks ago](https://wordpress.org/support/topic/patchstack-vulnerability-3/#post-18986654)
 * [@charactercreates](https://wordpress.org/support/users/charactercreates/) this
   is the same report indeed. I’ve been able to look at the report properly now.
   The issue has no further connections to access related to WordPress itself, just
   to calm everyone down.
 * The report is about communications with the Font Awesome API, which is needed
   to search for available icons when using the field.
 * I’ll be able to look into a potential fix this weekend.
 *  [charactercreates](https://wordpress.org/support/users/charactercreates/)
 * (@charactercreates)
 * [2 weeks ago](https://wordpress.org/support/topic/patchstack-vulnerability-3/#post-18986658)
 * Great, thanks.
 *  [nvkc](https://wordpress.org/support/users/nvkc/)
 * (@nvkc)
 * [1 week, 4 days ago](https://wordpress.org/support/topic/patchstack-vulnerability-3/#post-18989411)
 * This is still being reported for **6.1.2** as well.
 * [https://patchstack.com/database/wordpress/plugin/advanced-custom-fields-font-awesome/vulnerability/wordpress-advanced-custom-fields-font-awesome-field-plugin-6-1-1-broken-access-control-vulnerability](https://patchstack.com/database/wordpress/plugin/advanced-custom-fields-font-awesome/vulnerability/wordpress-advanced-custom-fields-font-awesome-field-plugin-6-1-1-broken-access-control-vulnerability)
 *  Plugin Author [Justin Kruit](https://wordpress.org/support/users/justinkruit/)
 * (@justinkruit)
 * [1 week, 4 days ago](https://wordpress.org/support/topic/patchstack-vulnerability-3/#post-18989492)
 * [@nvkc](https://wordpress.org/support/users/nvkc/) Correct, and I’m working on
   it. Although I do not fully agree with the new report; it states that Contributors
   can make calls to the Font Awesome API. But that is fully intended, as a contributor
   can come across a FA field in which case it needs access…

Viewing 6 replies - 1 through 6 (of 6 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fpatchstack-vulnerability-3%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/advanced-custom-fields-font-awesome/assets/icon-256x256.
   jpg?rev=3435775)
 * [Advanced Custom Fields: Font Awesome Field](https://wordpress.org/plugins/advanced-custom-fields-font-awesome/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/advanced-custom-fields-font-awesome/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/advanced-custom-fields-font-awesome/)
 * [Active Topics](https://wordpress.org/support/plugin/advanced-custom-fields-font-awesome/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/advanced-custom-fields-font-awesome/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/advanced-custom-fields-font-awesome/reviews/)

 * 8 replies
 * 4 participants
 * Last reply from: [Justin Kruit](https://wordpress.org/support/users/justinkruit/)
 * Last activity: [1 week, 4 days ago](https://wordpress.org/support/topic/patchstack-vulnerability-3/#post-18989492)
 * Status: not resolved