CVE-2026-25470: WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin < 2.0.52 - Remote Code Execution (RCE) vulnerability
Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ACPT (Pro) - Custom Post Types Plugin for WordPressto a version that resolves this vulnerability.Fixed in 2.0.52
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25470?
CVE-2026-25470 has a critical severity rating of 10.
How do I fix CVE-2026-25470?
To remediate CVE-2026-25470, update the ACPT (Pro) - Custom Post Types Plugin for WordPress to version 2.0.48 or later.
What systems are affected by CVE-2026-25470?
CVE-2026-25470 affects ACPT (Pro) - Custom Post Types Plugin for WordPress versions up to and including 2.0.47.
What type of vulnerability is CVE-2026-25470?
CVE-2026-25470 is a Remote Code Execution (RCE) vulnerability due to improper control of code generation.
Can CVE-2026-25470 lead to data breaches?
Yes, CVE-2026-25470 can potentially lead to data breaches as it allows for remote code inclusion.