Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-15354: ACPT Premium plugin lets strangers change any user’s password

CVE-2026-15354 · published 1 day ago
Summary

The ACPT Premium add‑on for WordPress lets anyone submit a form that can change the email address and password of any user, even an administrator. This happens because the plugin does not check who is making the request before updating the user record. To protect your site, update the plugin to a version that includes the fix or remove the public form if it isn’t needed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
mauro cassani acpt (premium) <= 2.0.66
Original advisory text
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which al...
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-15354 · MITRE
Monitor software like this
Free during beta