SQL Injection Vulnerability in ACPT (Pro) for WordPress
CVE-2026-32564
8.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 August 2026
What is CVE-2026-32564?
The ACPT (Pro) - Custom Post Types Plugin for WordPress versions up to 2.0.63 is susceptible to a SQL injection vulnerability that allows attackers to manipulate database queries. This flaw may enable unauthorized access to sensitive data and elevate privileges. Users of affected versions should apply updates or patches to mitigate potential exploitation.
Affected Version(s)
ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63