ACPT (Premium) WordPress Plugin Vulnerability: Critical Privilege Escalation
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- acpt (premium) plugin (wordpress)
- Patched version
- Not yet available
The ACPT (Premium) plugin for WordPress is under investigation for a critical vulnerability that allows unauthenticated attackers to escalate privileges and take over any user account.
What happened
An early warning has been issued for a critical vulnerability in the ACPT (Premium) plugin for WordPress. This vulnerability, tracked as CVE-2026-15354, reportedly allows unauthenticated attackers to escalate privileges by overwriting any user's email address and password, including administrators. The affected versions are all up to, and including, 2.0.66. The vulnerability is due to missing authorization in the `submit()` function.
The severity of this vulnerability is high, with a CVSS score of 9.8. It is crucial for users of the ACPT (Premium) plugin to assess their exposure and take immediate action to mitigate the risk.
What to do about it
- Check the version of the ACPT (Premium) plugin currently installed on your WordPress site.
- If your version is 2.0.66 or earlier, upgrade to a version that addresses the missing authorization in the `submit()` function.
- Monitor the NVD page for CVE-2026-15354 for updates on a patched version.
- In the absence of an official fix, consider disabling the ACPT (Premium) plugin until a secure version is available.
- Review your WordPress site's security settings and ensure that all other plugins and themes are up to date.
How 0Day would have caught this
acpt (premium) plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the ACPT (Premium) plugin for WordPress and your version is 2.0.66 or earlier, you are potentially affected.
What should I do right now?
Immediately check your plugin version and upgrade to a secure version if available. If no secure version is available, consider disabling the plugin.
Is there a patched version available?
No official fix has been published yet. Monitor the NVD page for CVE-2026-15354 for updates.