Remote Code Execution Vulnerability in ACPT Premium Plugin for WordPress
CVE-2026-105701
8.8HIGH
What is CVE-2026-105701?
The ACPT Premium Plugin for WordPress is susceptible to Remote Code Execution across all versions up to and including 2.0.66. This vulnerability arises from a lack of proper capability checks in the REST API form creation endpoint, combined with unsandboxed rendering of email templates using Twig. Authenticated attackers with subscriber-level access or higher can exploit this weakness by first creating a form containing malicious email settings. Upon triggering form submission, these attackers can execute arbitrary code on the server by injecting harmful Twig expressions, leading to potential system compromise.
Affected Version(s)
ACPT (Premium) 0 <= 2.0.66