CVE-2026-32564 HIGH

CVE-2026-32564: WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection vulnerability

Vendor Acpt
Product ACPT (Pro) - Custom Post Types Plugin for WordPress
Weakness CWE-89 · SQLi
Published August 27, 2026
Last update August 27, 2026

CVSS base score

8.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

Explanation of Vulnerability in Simple Terms

02Summary

The ACPT (Pro) Custom Post Types plugin for WordPress versions up to 2.0.63 contains a SQL injection vulnerability in a component requiring low-level authentication. An authenticated attacker can craft malicious input to execute arbitrary SQL queries, potentially reading sensitive database content or disrupting site availability. The vulnerability affects multiple users and components due to scope change.

What an attacker can do

03Attacker Capabilities

Read sensitive database content or cause the site database to become unavailable.

Potential impact on your site

04Site Impact

Attackers with basic WordPress accounts can steal data from your database or crash your site's database functionality.

Conditions required to exploit

05Prerequisites

Attacker must have a WordPress user account with low-level privileges (e.g., subscriber or contributor role).

Key dates

06Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated