CVE-2026-25470Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-18: 1Patch / Workaround · 2026-06-18: 1Technical Details · 2026-06-18: 106-18
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecAlerts@SecAlertsCo
    Disclosure

    🔓 Unauthenticated RCE in ACPT (Pro) - Custom Post Types plugin for WordPress (<=2.0.47). Code injection, CVSS 10, no auth required. Update immediately. CVE-2026-25470 https://secalerts.co/vulnerability/CVE-2026-25470 https://t.co/om0GWzYx2a

    Post summary

    The message announces an unauthenticated remote code execution vulnerability (CVE‑2026‑25470) in the ACPT WordPress plugin, provides key technical details, and urges users to apply an update immediately.

    0100076
    838 followersView on X

Explore more