Privilege Escalation Vulnerability in ACPT Plugin for WordPress
CVE-2026-15354
9.8CRITICAL
What is CVE-2026-15354?
The ACPT (Premium) plugin for WordPress contains a vulnerability that allows unauthorized users to perform Privilege Escalation. This is primarily due to a lack of proper authorization checks in the 'submit()' function. Attackers can exploit this by submitting an unauthorized form to gain control over user accounts, effectively enabling them to change email addresses and passwords of any WordPress user, including administrators. Successful exploitation necessitates that a public ACPT user form is available, which allows anonymous submissions.
Affected Version(s)
ACPT (Premium) 0 <= 2.0.66