CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105701

HIGHCVSS 8.8NVD feed

Published 6 October 2026 · tracked since 7 October 2026

Description

The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes i

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105701 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105701

HIGHCVSS 8.8NVD feed

Published 6 October 2026 · tracked since 7 October 2026

Description

The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes i

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]