Impact
Based on the updated description, an unauthenticated Remote Code Execution vulnerability exists in ACPT (Pro) - Custom Post Types Plugin for WordPress for versions up to and including 2.0.47. The flaw permits attackers to execute arbitrary code on the hosting server, compromising confidentiality, integrity, and availability of the WordPress site.
Affected Systems
WordPress sites that have installed the ACPT (Pro) plugin on any version up to and including 2.0.47. Each occurrence of the plugin in any content, admin, or user-facing area is vulnerable.
Risk and Exploitability
The CVSS score of 10 and a EPSS score of less than 1% suggest that the vulnerability is rarely reported or exploited in the wild at present. It is not listed in the CISA KEV catalog, yet the remote code execution nature and high base severity make it a priority target for attackers. Likely exploitation would involve sending crafted input via HTTP requests to the plugin’s endpoints or configuration interfaces, causing the server to evaluate the injected code.
OpenCVE Enrichment