CVE-2026-32566

9.8

ACPT · ACPT (Pro) - Custom Post Types Plugin for WordPress

A critical privilege escalation vulnerability in the ACPT (Pro) WordPress plugin allows unauthenticated attackers to gain unauthorized administrative access.

Executive summary

An unauthenticated privilege escalation vulnerability in the ACPT (Pro) WordPress plugin allows remote attackers to compromise the entire site by gaining administrative control.

Vulnerability

This vulnerability is an incorrect privilege assignment (CWE-266) that permits unauthenticated remote attackers to escalate their privileges to administrative levels without requiring any user interaction.

Business impact

The potential for unauthenticated privilege escalation represents a critical security risk, as it grants attackers full control over the affected WordPress instance. With administrative access, malicious actors can exfiltrate sensitive data, inject backdoors, or deploy ransomware, leading to significant reputational damage and operational downtime. Given the CVSS score of 9.8, this flaw poses an immediate threat to the confidentiality, integrity, and availability of the host environment.

Remediation

Immediate Action: Update the ACPT (Pro) plugin to the latest available version provided by the vendor to remediate the privilege assignment flaw.

Proactive Monitoring: Monitor server access logs for anomalous registration attempts or unexpected changes to user roles and privileges within the WordPress administrative panel.

Compensating Controls: Implement a Web Application Firewall (WAF) to detect and block malicious requests targeting known plugin endpoints until the update can be applied.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Due to the critical nature of this privilege escalation flaw and the lack of authentication required for exploitation, immediate action is necessary. Security teams should prioritize updating the ACPT (Pro) plugin across all affected WordPress installations to ensure that the vulnerability is fully patched. Failure to address this risk promptly leaves the underlying system exposed to complete administrative takeover.

More ACPT CVEs