What the vulnerability does
01Description
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Explanation of Vulnerability in Simple Terms
The ACPT Custom Post Types plugin for WordPress versions up to 2.0.63 assigns excessive privileges to unauthenticated users, allowing them to read, modify, and delete site data without logging in. The vulnerability stems from incorrect privilege checks in the plugin's core functionality. An attacker can exploit this remotely without user interaction to compromise the entire site.
What an attacker can do
Read, modify, and delete any site data including posts, users, and settings without authentication.
Potential impact on your site
Complete compromise of site data and functionality. Attackers can deface content, steal information, delete posts, or modify user accounts.
Conditions required to exploit
None. The attacker needs only network access to the WordPress site.
Key dates
External resources
Related vulnerabilities