PT-2026-50086 · WordPress · Acpt
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ACPT (Pro) - Custom Post Types Plugin for WordPress versions prior to 2.0.48
Description
Improper Control of Generation of Code allows for Remote Code Inclusion and unauthenticated Remote Code Execution (RCE). This issue enables an attacker to inject malicious code into the system without requiring authentication.
Recommendations
Update the plugin to a version later than 2.0.47.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acpt