PT-2025-48013 · WordPress · Ace Post Type Builder

Abhirup Konwar

·

Published

2025-11-25

·

Updated

2025-11-25

·

CVE-2025-13405

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ace Post Type Builder plugin for WordPress versions prior to 1.9
Description The Ace Post Type Builder plugin for WordPress has an issue where custom taxonomies can be deleted without proper authorization. This is due to a missing authorization check in the cptb delete custom taxonomy() function. Attackers with Subscriber-level access or higher can delete arbitrary custom taxonomies.
Recommendations Update to a version beyond 1.9.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13405

Affected Products

Ace Post Type Builder