Skip to main content
QUIETLYTIC
Vulnerability

ACPT- Custom Post Types Plugin for WordPress Privilege Escalation (CVE-2026-32566)

CVE-2026-32566 is a CVSS 9.8 unauthenticated privilege escalation flaw in the ACPT Pro WordPress plugin, reported exploited by VulnCheck KEV.

CVE-2026-32566
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
ACPT (Pro) - Custom Post Types Plugin for WordPress, ACPT (Pro) (through 2.0.63)

CVE-2026-32566 carries a CVSS 3.1 base score of 9.8 against ACPT (Pro) - Custom Post Types Plugin for WordPress, a plugin for building custom content types and fields. NVD classifies it as CWE-266 (Incorrect Privilege Assignment) and states the affected range as versions up to and including 2.0.63. VulnCheck’s KEV feed reports the CVE as exploited, dated August 28, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-32566 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s own summary is brief but specific: an unauthenticated privilege escalation in ACPT (Pro) versions through 2.0.63. Patchstack’s vulnerability database, cited directly from NVD’s reference list, tracks this under the same CWE-266 classification our source data carries. NVD’s record does not describe the internal mechanism beyond the classification itself — that a privilege-assignment check the plugin should perform is either missing or incorrectly scoped, allowing an unauthenticated visitor to obtain elevated privileges without NVD’s summary specifying which privileged action or role is reachable.

We report NVD’s classification and affected-version boundary as stated rather than speculating about the missing mechanism detail — a gap we flag explicitly rather than fill with a plausible-sounding guess.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-266 classification, and the affected-version ceiling (2.0.63) all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.0045, a 38.2nd percentile score as of our ingestion.

No field is in conflict between our two sources. Our data carries no fixed-version field; NVD’s summary states only the affected ceiling.

Why this matters

An unauthenticated privilege escalation in a widely used WordPress plugin category — custom post types and content-modeling tools are common on business and publishing sites — is a high-value target precisely because it requires no prior foothold: no stolen credentials, no social engineering, nothing beyond reaching the site’s front end. The lack of a described mechanism in NVD’s summary makes this harder for a site operator to reason about independently, which is itself a reason to treat the CVSS score and exploitation report as sufficient grounds to act rather than waiting to understand exactly how the flaw is reached.

Because NVD names only an affected-version ceiling rather than a stated fix, operators should confirm directly with the plugin’s changelog or vendor page whether a version past 2.0.63 addresses this, rather than assuming version 2.0.64 or later is automatically safe.

Frequently Asked Questions

What is CVE-2026-32566? A CVSS 9.8 unauthenticated privilege escalation vulnerability (CWE-266) in the ACPT (Pro) - Custom Post Types Plugin for WordPress, affecting versions up to and including 2.0.63.

Is CVE-2026-32566 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 28, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

What exactly does the attacker gain? NVD’s record classifies the flaw as incorrect privilege assignment but does not specify the exact privileged action reached. We report this gap rather than speculate about the mechanism.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our data carries no fixed-version field. NVD states versions through 2.0.63 are affected; confirm directly with the vendor’s changelog whether a later release addresses this specific CVE.


Severity, vector, weakness classification, and affected-version ceiling sourced from the National Vulnerability Database record for CVE-2026-32566, which cites Patchstack’s vulnerability database entry. Exploitation status and the August 28, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools