PT-2025-48013 · WordPress · Ace Post Type Builder

·

CVE-2025-13405

·

Published

2025-11-25

·

Updated

2025-11-25

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ace Post Type Builder plugin for WordPress versions prior to 1.9
Description The Ace Post Type Builder plugin for WordPress has an issue where custom taxonomies can be deleted without proper authorization. This is due to a missing authorization check in the cptb delete custom taxonomy() function. Attackers with Subscriber-level access or higher can delete arbitrary custom taxonomies.
Recommendations Update to a version beyond 1.9.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13405

Affected Products

Ace Post Type Builder