SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-32563

CRITICAL · CVSS 9.8 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Custom Post Types Plugin for WordPress versions up to 2.0.63 is vulnerable to a PHP Object Injection flaw that allows unauthenticated attackers to execute arbitrary PHP code. This critical vulnerability poses a significant risk of remote code execution, potentially compromising the integrity and availability of affected WordPress sites. WordPress administrators and developers using this plugin should prioritize immediate updates to mitigate the risk.

CVE
CVE-2026-32563
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%
WordPress

Original NVD Description

Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.