WORDPRESS · SEPTEMBER 2026 · EARLY WARNING

ACPT (Premium) WordPress Plugin Vulnerability: Critical Privilege Escalation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
acpt (premium) plugin (wordpress)
Patched version
Not yet available
CVE-2026-15354

The ACPT (Premium) plugin for WordPress is under investigation for a critical vulnerability that allows unauthenticated attackers to escalate privileges and take over any user account.

What happened

An early warning has been issued for a critical vulnerability in the ACPT (Premium) plugin for WordPress. This vulnerability, tracked as CVE-2026-15354, reportedly allows unauthenticated attackers to escalate privileges by overwriting any user's email address and password, including administrators. The affected versions are all up to, and including, 2.0.66. The vulnerability is due to missing authorization in the `submit()` function.

The severity of this vulnerability is high, with a CVSS score of 9.8. It is crucial for users of the ACPT (Premium) plugin to assess their exposure and take immediate action to mitigate the risk.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If acpt (premium) plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the ACPT (Premium) plugin for WordPress and your version is 2.0.66 or earlier, you are potentially affected.

What should I do right now?

Immediately check your plugin version and upgrade to a secure version if available. If no secure version is available, consider disabling the plugin.

Is there a patched version available?

No official fix has been published yet. Monitor the NVD page for CVE-2026-15354 for updates.

Sources

Join the 0Day waitlist →

← Back to all threats