CVE-2026-32563: WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability
Published Aug 24, 2026
·Updated
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Affected Software
1 affected component
WordPress ACPT (Pro) - Custom Post Types Plugin<=2.0.63
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which plugin versions are affected?
ACPT (Pro) - Custom Post Types Plugin for WordPress versions 2.0.63 and earlier are affected.
2
What level of access does an attacker need?
The issue is described as subscriber PHP object injection. This indicates that a subscriber-level account can be used to exploit the vulnerability.
3
Can this be exploited remotely without user interaction?
Yes. The supplied CVSS vector indicates network-based exploitation with low attack complexity, no user interaction, and no privileges required.
4
What is the potential impact?
The supplied severity data rates the issue critical at 9.8 and indicates high impact to confidentiality, integrity, and availability.