CVE-2026-25470: WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin <= 2.0.47 - Remote Code Execution (RCE) vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion.
This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ACPT (Pro) - Custom Post Types Plugin for WordPressfrom your environment.Uninstall or deactivate the ACPT (Pro) - Custom Post Types Plugin for WordPress if present. This plugin is vulnerable in versions up to and including 2.0.47; remove any installed instance at or below 2.0.47.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25470?
CVE-2026-25470 has a critical severity rating of 10.
How do I fix CVE-2026-25470?
To remediate CVE-2026-25470, update the ACPT (Pro) - Custom Post Types Plugin for WordPress to version 2.0.48 or later.
What systems are affected by CVE-2026-25470?
CVE-2026-25470 affects ACPT (Pro) - Custom Post Types Plugin for WordPress versions up to and including 2.0.47.
What type of vulnerability is CVE-2026-25470?
CVE-2026-25470 is a Remote Code Execution (RCE) vulnerability due to improper control of code generation.
Can CVE-2026-25470 lead to data breaches?
Yes, CVE-2026-25470 can potentially lead to data breaches as it allows for remote code inclusion.