Remote Code Execution Vulnerability in ACPT Premium Plugin for WordPress
CVE-2026-105701

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105701?

The ACPT Premium Plugin for WordPress is susceptible to Remote Code Execution across all versions up to and including 2.0.66. This vulnerability arises from a lack of proper capability checks in the REST API form creation endpoint, combined with unsandboxed rendering of email templates using Twig. Authenticated attackers with subscriber-level access or higher can exploit this weakness by first creating a form containing malicious email settings. Upon triggering form submission, these attackers can execute arbitrary code on the server by injecting harmful Twig expressions, leading to potential system compromise.

Affected Version(s)

ACPT (Premium) 0 <= 2.0.66

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d.v4n_s3c
.