← Back to overview

A critical unauthenticated privilege escalation vulnerability has been identified in the ACPT (Pro) - Custom Post Types Plugin for WordPress, affecting versions up to and including 2.0.63. The vulnerability allows unauthenticated attackers to escalate their privileges, potentially gaining administrative access to affected WordPress installations. This type of vulnerability is particularly dangerous as it requires no prior authentication or user interaction to exploit. The issue has been assigned CVE-2026-32566 and is documented by both the NVD and Patchstack. WordPress site administrators using the ACPT Pro plugin should update to a patched version immediately. The vulnerability was rated High severity given the unauthenticated nature and the potential for full site compromise.

Affected products

  • ACPT Pro - Custom Post Types Plugin for WordPress <= 2.0.63

Related CVE's

  • CVE-2026-32566

Categories

  • Identity & Access
  • Web Technologies