CVE-2026-15354

The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 07:17

Updated : 2026-09-04 19:17


NVD link : CVE-2026-15354

Mitre link : CVE-2026-15354

CVE.ORG link : CVE-2026-15354


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management