CRITICAL
9.8 CVE-2026-15354 Published 4 Sept 2026
WordPress ACPT Premium Plugin Privilege Escalation
Worried this affects one of your servers?
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66.
This is due to missing authorization in the submit() function, which allows unauthenticated form submissions to control the target user ID before calling wp_update_user().
This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account.
Successful exploitation requires a public ACPT user form that permits anonymous submissions.
Reference: CVE-2026-15354 on NVD
← Back to Security News