SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-32564

HIGH · CVSS 8.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The ACPT (Pro) - Custom Post Types Plugin for WordPress versions up to 2.0.63 is vulnerable to a Subscriber-level SQL Injection, allowing attackers to manipulate database queries and potentially gain unauthorized access to sensitive data. This high-severity vulnerability poses a significant risk to WordPress sites using the affected plugin, particularly those with low-level user roles. WordPress administrators and site owners utilizing this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-32564
Severity
HIGH
CVSS
8.5
EPSS
0.34%
WordPress

Original NVD Description

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.