PatchSiren

ACPT CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL ACPT CVE published 2026-06-17

CVE-2026-25470

A critical vulnerability was found in the ACPT (Pro) - Custom Post Types Plugin for WordPress, which allows unauthenticated remote code execution. This issue affects versions up to 2.0.47 and has a CVSS score of 10.