Executive brief
ACPT (Pro) is a WordPress plugin that allows site administrators to create custom post types. A SQL injection vulnerability in this plugin allows attackers with a subscriber-level account (the lowest privilege level) to read, modify, or delete the entire website database, including user credentials and private customer data. This poses a critical risk to any WordPress site using the plugin.
Technical details
The plugin contains a SQL injection vulnerability that is accessible to authenticated users with the Subscriber role. The vulnerability exists in the custom post type handling code and allows an attacker to inject arbitrary SQL commands. An attacker with a subscriber account can exploit this to extract sensitive data from the database, modify or delete records, or potentially escalate privileges. No official patch was available at the time of disclosure (August 2026); remediation requires immediate plugin update or disabling the plugin until a fix is released.
Affected products
- ACPT ACPT (Pro) - Custom Post Types Plugin <= 2.0.63
Timeline
- 2026-08-25: disclosed: Reported by VDsec
- 2026-08-27: advisory: Published on NVD and Patchstack