PT-2026-82445 · WordPress · Acpt (Pro) - Custom Post Types Plugin

CVE-2026-32566

·

Published

2026-08-27

·

Updated

2026-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ACPT (Pro) - Custom Post Types Plugin for WordPress versions prior to 2.0.64
Description An unauthenticated privilege escalation issue allows an attacker to create a WordPress administrator account. This flaw has been exploited in the wild via two different routes: the REST API and the admin-ajax endpoint. In observed incidents, attackers set the administrator password to "solevisible" to deploy ALFA-Shell, a known WordPress webshell.
Recommendations Update ACPT (Pro) - Custom Post Types Plugin for WordPress to version 2.0.64 or later.

Fix

LPE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32566

Affected Products

Acpt (Pro) - Custom Post Types Plugin