Privilege Escalation Vulnerability in ACPT Plugin for WordPress
CVE-2026-15354

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 September 2026

What is CVE-2026-15354?

The ACPT (Premium) plugin for WordPress contains a vulnerability that allows unauthorized users to perform Privilege Escalation. This is primarily due to a lack of proper authorization checks in the 'submit()' function. Attackers can exploit this by submitting an unauthorized form to gain control over user accounts, effectively enabling them to change email addresses and passwords of any WordPress user, including administrators. Successful exploitation necessitates that a public ACPT user form is available, which allows anonymous submissions.

Affected Version(s)

ACPT (Premium) 0 <= 2.0.66

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d.v4n_s3c
.