SQL Injection Vulnerability in ACPT (Pro) for WordPress
CVE-2026-32564

8.5HIGH

What is CVE-2026-32564?

The ACPT (Pro) - Custom Post Types Plugin for WordPress versions up to 2.0.63 is susceptible to a SQL injection vulnerability that allows attackers to manipulate database queries. This flaw may enable unauthorized access to sensitive data and elevate privileges. Users of affected versions should apply updates or patches to mitigate potential exploitation.

Affected Version(s)

ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VDsec | Patchstack Bug Bounty Program
.