The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 07:17
Updated : 2026-09-04 19:17
NVD link : CVE-2026-15354
Mitre link : CVE-2026-15354
CVE.ORG link : CVE-2026-15354
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management
