Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mauro Cassani
Mauro Cassani acpt (premium) Wordpress Wordpress wordpress |
|
| Vendors & Products |
Mauro Cassani
Mauro Cassani acpt (premium) Wordpress Wordpress wordpress |
Fri, 04 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions. | |
| Title | ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-04T18:36:32.080Z
Reserved: 2026-07-10T00:10:11.358Z
Link: CVE-2026-15354
Updated: 2026-09-04T18:36:28.935Z
Status : Deferred
Published: 2026-09-04T07:17:08.487
Modified: 2026-09-04T19:17:22.257
Link: CVE-2026-15354
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:20:20Z