CVE-2026-32563 describes a PHP Object Injection vulnerability in the ACPT (Pro) - Custom Post Types Plugin for WordPress, affecting versions up to and including 2.0.63. The vulnerability can be exploited by subscriber-level authenticated users, allowing them to inject PHP objects. PHP Object Injection vulnerabilities can lead to a variety of attacks depending on available POP chains in the environment, including remote code execution, file manipulation, or privilege escalation. The issue was reported via the Patchstack vulnerability database and catalogued on the NVD. WordPress site administrators running the affected plugin version should update to a patched version immediately. The vulnerability is rated as high severity.