VYPR

ACPT

by WordPress

CVEs (1)

  • CVE-2026-15354CriSep 4, 2026
    risk 0.64cvss 9.8epss

    The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling…