Junglewise Threat Intelligence

CVE-2026-25470: ACPT Custom Post Types Plugin for WordPress remote code execution

CVE-2026-25470 · Severity: critical · CVSS 10 · Published 2026-06-17

Executive brief

A critical security flaw has been identified in the ACPT (Pro) plugin for WordPress, which is used to manage custom post types and site content. This vulnerability allows an unauthorized attacker to remotely execute malicious code on the web server. If exploited, an attacker could gain full control over the website, steal sensitive customer data, or cause a complete service outage.

Technical details

The ACPT (Pro) plugin for WordPress (versions up to 2.0.47) is vulnerable to Remote Code Execution (RCE) due to improper control of code generation (CWE-94). The flaw allows an unauthenticated attacker to inject and execute arbitrary code via the network without any user interaction. This is classified as a high-priority vulnerability with a CVSS score of 10.0, as it provides a path for complete system compromise. As of the advisory date, no official patch has been released by the developer, and users are advised to seek alternative mitigation strategies such as web application firewalls.

Affected products

  • ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress up to 2.0.47

Timeline

  • 2025-12-16: other: Vulnerability reported by researcher Jarno Vos
  • 2026-03-16: advisory: Patchstack published initial advisory
  • 2026-06-17: disclosed: CVE published to NVD

References