Impact
The ACPT (Premium) WordPress plugin is vulnerable to privilege escalation in all versions up to and including 2.0.66. Because the submit() function omits authorization checks, an unauthenticated user can submit a form that sets the target user ID and then triggers wp_update_user(). This allows the attacker to overwrite any WordPress user's email address and password, including that of an administrator, effectively taking over the account. The flaw is a direct result of missing authorization, corresponding to CWE‑269.
Affected Systems
Mauro Cassani’s ACPT (Premium) plugin for WordPress. Versions 2.0.66 and earlier are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the flaw requires only an unauthenticated HTTP request to a publicly reachable form that permits anonymous submissions. The vulnerability is not listed in the CISA KEV catalog, but its impact and high CVSS make it a high‑risk target. Attackers can gain full control over any user account, leading to complete compromise of the affected WordPress site.
OpenCVE Enrichment