Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-32566: WordPress ACPT Pro plugin can let attackers gain admin rights
CVE-2026-32566 · published 7 days ago
Summary
The ACPT Pro custom post types plugin for WordPress, up to version 2.0.63, can be tricked by anyone on the internet to give themselves higher privileges on your site. This means an attacker could take control of your website, add or change content, and access sensitive data. Update the plugin to the latest version or remove it if you don’t need it, and review user accounts for any unauthorized changes.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| acpt | acpt (pro) - custom post types plugin for wordpress | <= 2.0.63 |
Original advisory text
WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published27 Aug 2026
Updated2 Sep 2026
First seen27 Aug 2026
Monitor software like this
Free during beta