CVE-2026-32564: WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection vulnerability
Published Aug 27, 2026
·Updated
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Affected Software
1 affected component
WordPress ACPT (Pro) - Custom Post Types Plugin<=2.0.63
Event History
Aug 27, 2026
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker needs a WordPress account with Subscriber-level privileges. The attack can be performed remotely and does not require user interaction.
2
Which plugin versions are affected?
ACPT (Pro) - Custom Post Types Plugin for WordPress versions 2.0.63 and earlier are affected.
3
What is the potential impact?
Successful exploitation can expose highly sensitive information and may cause limited availability impact. The vulnerability has a CVSS severity of High (8.5) and has scope change.