PHP Object Injection in ACPT Plugin for WordPress
CVE-2026-32563
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 August 2026
What is CVE-2026-32563?
The ACPT (Pro) - Custom Post Types Plugin for WordPress is vulnerable to PHP Object Injection in versions up to 2.0.63. This issue allows attackers to manipulate the object to execute arbitrary code through crafted input, potentially compromising the security of WordPress sites utilizing this plugin. Further investigation and remediation are essential to ensure the safety of affected installations.
Affected Version(s)
ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63