CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105701
HIGHCVSS 8.8NVD feed
Published 6 October 2026 · tracked since 7 October 2026
Description
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes i
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-4889
- CVE-2026-41559 HIGH 7.5
- CVE-2026-39797 CRITICAL 9.8
- CVE-2026-39775 HIGH 8.8
- CVE-2026-39752 HIGH 7.7
- CVE-2026-39728 HIGH 7.2
- CVE-2026-32579 CRITICAL 10
- CVE-2026-105808 LOW 3.5
- CVE-2026-105809 MEDIUM 4.3
- CVE-2026-105059 MEDIUM 6.5