The ACPT (Premium) plugin for WordPress contains a critical privilege escalation vulnerability affecting all versions up to and including 2.0.66. The flaw resides in the submit() function, which lacks proper authorization checks, allowing unauthenticated attackers to manipulate the target user ID in form submissions. By exploiting this, an attacker can overwrite any WordPress user's email address and password, including administrator accounts, effectively taking full control. Exploitation is possible when a public ACPT user form that permits anonymous submissions is present on the site. This vulnerability enables complete account takeover without any prior authentication. The issue has been documented by both NVD and Wordfence threat intelligence. Site administrators are urged to update beyond version 2.0.66 immediately to mitigate risk.