CVE-2026-15354
Received Received - Intake

Privilege Escalation in ACPT WordPress Plugin

Vulnerability report for CVE-2026-15354, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: Wordfence

Description

The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
acpt plugin to 2.0.66 (inc)
acpt plugin to 2.0.67 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation flaw in the ACPT WordPress plugin versions up to 2.0.66. It allows unauthenticated attackers to submit forms that manipulate user IDs and call wp_update_user() without proper authorization. This can let attackers change any user's email and password, including administrators, effectively taking over accounts.

Detection Guidance

Check if the ACPT WordPress plugin is installed and verify its version. If it is version 2.0.66 or lower, the system is vulnerable. Look for unauthorized user account changes or suspicious form submissions in WordPress logs.

Impact Analysis

If exploited, attackers can gain full control of WordPress user accounts, including admin accounts. This could lead to website takeover, data theft, unauthorized modifications, or complete compromise of the site. The attack requires a public ACPT form allowing anonymous submissions.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive user data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Update the ACPT plugin to the latest patched version immediately. If updating is not possible, disable the plugin temporarily until an update is available. Review WordPress user accounts for unauthorized changes and remove any suspicious admin accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15354. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart