← Back to browse · API

CVE-2026-25470

Severity
CRITICAL
CVSS
10.0
EPSS
0.00428
Risk score
40.15
CISA KEV
No
PoC
No
Published
2026-06-16
Modified
2026-06-17
First seen
2026-08-07
Aliases
EUVD-2026-37503, GHSA-3XC6-WGX8-2FFV
Products
ACPT:ACPT (Pro) - Custom Post Types Plugin for WordPress n/a ≤2.0.47
Sources
euvd EUVD-2026-37503

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.

References