Executive brief
ACPT Pro is a popular WordPress plugin for creating and managing custom post types. This vulnerability allows any unauthenticated attacker to escalate their privileges to administrator, gaining full control of an affected WordPress site including access to all content, user accounts, and configuration. With a CVSS score of 9.8 and already exploited in the wild, this poses an immediate and severe risk to website integrity and customer data security.
Technical details
This is an unauthenticated privilege escalation vulnerability in the ACPT Pro WordPress plugin affecting versions 2.0.66 and earlier. The vulnerability is rooted in identification and authentication failures (OWASP A7) and allows an unauthenticated attacker to escalate their privileges to administrator level without requiring any prior access or credentials. The attack is network-accessible and requires no user interaction. Successful exploitation grants an attacker full administrative control over the WordPress installation, enabling them to modify site content, steal data, install malware, or deface the website. The issue is patched in version 2.0.67 and later; immediate upgrade is strongly recommended.
Affected products
- ACPT Pro Custom Post Types <= 2.0.66
Timeline
- 2026-08-25: disclosed
- 2026: patched: Version 2.0.67 and later