CVE-2026-32566: WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability
Published Aug 27, 2026
·Updated
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Affected Software
1 affected component
WordPress/ACPT (Pro) - Custom Post Types Plugin<=2.0.63
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ACPT (Pro) - Custom Post Types Pluginto a version that resolves this vulnerability.Fixed in 2.0.63
Event History
Aug 27, 2026
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or existing privileges to attempt exploitation.
2
Which installations are affected?
WordPress sites using ACPT (Pro) - Custom Post Types Plugin version 2.0.63 or earlier are affected according to the provided data.
3
What level of impact could successful exploitation have?
Successful exploitation can result in privilege escalation and is rated critical, with high confidentiality, integrity, and availability impact.