
SecAlerts@SecAlertsCo
Disclosure
🔓 Unauthenticated RCE in ACPT (Pro) - Custom Post Types plugin for WordPress (<=2.0.47). Code injection, CVSS 10, no auth required. Update immediately. CVE-2026-25470 https://secalerts.co/vulnerability/CVE-2026-25470 https://t.co/om0GWzYx2a
Post summary
The message announces an unauthenticated remote code execution vulnerability (CVE‑2026‑25470) in the ACPT WordPress plugin, provides key technical details, and urges users to apply an update immediately.
0100076
838 followersView on X
