Description
Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.
Published: 2026-06-16
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Based on the updated description, an unauthenticated Remote Code Execution vulnerability exists in ACPT (Pro) - Custom Post Types Plugin for WordPress for versions up to and including 2.0.47. The flaw permits attackers to execute arbitrary code on the hosting server, compromising confidentiality, integrity, and availability of the WordPress site.

Affected Systems

WordPress sites that have installed the ACPT (Pro) plugin on any version up to and including 2.0.47. Each occurrence of the plugin in any content, admin, or user-facing area is vulnerable.

Risk and Exploitability

The CVSS score of 10 and a EPSS score of less than 1% suggest that the vulnerability is rarely reported or exploited in the wild at present. It is not listed in the CISA KEV catalog, yet the remote code execution nature and high base severity make it a priority target for attackers. Likely exploitation would involve sending crafted input via HTTP requests to the plugin’s endpoints or configuration interfaces, causing the server to evaluate the injected code.

Generated by OpenCVE AI on September 21, 2026 at 07:27 UTC.

Remediation

Vendor Solution

Update the WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin to the latest available version (at least 2.0.52).


OpenCVE Recommended Actions

  • Update the ACPT (Pro) plugin to the latest release that removes the code injection flaw.
  • If an immediate update is not feasible, disable or uninstall the plugin entirely until a fix is available.
  • Restrict plugin usage and configuration to trusted administrators and block or sanitize any user-supplied input that the plugin processes.

Generated by OpenCVE AI on September 21, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47. Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.
Title WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin <= 2.0.47 - Remote Code Execution (RCE) vulnerability WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin < 2.0.52 - Remote Code Execution (RCE) vulnerability

Sun, 21 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Acpt
Acpt acpt (pro) - Custom Post Types Plugin For Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Acpt
Acpt acpt (pro) - Custom Post Types Plugin For Wordpress
Wordpress
Wordpress wordpress

Wed, 17 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.
Title WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin <= 2.0.47 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Acpt Acpt (pro) - Custom Post Types Plugin For Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-14T14:57:14.993Z

Reserved: 2026-02-02T12:53:59.642Z

Link: CVE-2026-25470

cve-icon Vulnrichment

Updated: 2026-06-17T10:35:35.375Z

cve-icon NVD

Status : Deferred

Published: 2026-06-17T13:20:11.603

Modified: 2026-09-14T15:17:04.963

Link: CVE-2026-25470

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:30:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')