PT-2026-82445 · WordPress · Acpt (Pro) - Custom Post Types Plugin
CVE-2026-32566
·
Published
2026-08-27
·
Updated
2026-09-03
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ACPT (Pro) - Custom Post Types Plugin for WordPress versions prior to 2.0.64
Description
An unauthenticated privilege escalation issue allows an attacker to create a WordPress administrator account. This flaw has been exploited in the wild via two different routes: the REST API and the
admin-ajax endpoint. In observed incidents, attackers set the administrator password to "solevisible" to deploy ALFA-Shell, a known WordPress webshell.Recommendations
Update ACPT (Pro) - Custom Post Types Plugin for WordPress to version 2.0.64 or later.
Fix
LPE
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acpt (Pro) - Custom Post Types Plugin