Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-32566: WordPress ACPT Pro plugin can let attackers gain admin rights

CVE-2026-32566 · published 7 days ago
Summary

The ACPT Pro custom post types plugin for WordPress, up to version 2.0.63, can be tricked by anyone on the internet to give themselves higher privileges on your site. This means an attacker could take control of your website, add or change content, and access sensitive data. Update the plugin to the latest version or remove it if you don’t need it, and review user accounts for any unauthorized changes.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
acpt acpt (pro) - custom post types plugin for wordpress <= 2.0.63
Original advisory text
WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published27 Aug 2026
Updated2 Sep 2026
First seen27 Aug 2026
Sources
CVE-2026-32566 · MITRE
Monitor software like this
Free during beta