Remote Code Execution in ACPT (Premium) WordPress Plugin
Authenticated attackers with subscriber-level access can achieve remote code execution in ACPT (Premium) versions up to 2.0.66 by injecting malicious Twig expressions via the REST API.
CVE search metadata
CVE search record: CVE-2026-105701. Severity: high. CVSS: 8.8. KEV: no. Product: ACPT (Premium) (<= 2.0.66). Brief: Remote Code Execution in ACPT (Premium) WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-acpt-rce/
The ACPT (Premium) plugin for WordPress contains a critical vulnerability (CVE-2026-105701) that allows authenticated attackers with subscriber-level access or higher to execute arbitrary code on the underlying server. The flaw exists due to a missing capability check on the REST API endpoint responsible for form creation. This endpoint fails to properly validate the user's permissions, allowing the injection of malicious payloads within the email_settings parameter. Because the plugin utilizes an unsandboxed Twig template rendering environment for these email templates, an attacker can craft specifically formatted Twig expressions that are executed server-side. This vulnerability affects all versions of the ACPT (Premium) plugin up to and including 2.0.66. Successful exploitation requires an attacker to first create a malicious form object via the REST API and then trigger the form submission process, which forces the rendering engine to process the injected code.
Impact
Successful exploitation results in full Remote Code Execution (RCE) on the WordPress server. As WordPress typically runs with the permissions of the web server user (such as www-data), an attacker can read sensitive files, modify site content, pivot to the internal network, or deploy persistent backdoors. Given the ubiquity of WordPress installations, this vulnerability poses a high risk for sites utilizing the ACPT Premium plugin for form management.
Recommendation
- Upgrade the ACPT (Premium) plugin to a version released after 2.0.66 immediately to receive the security patch.
- Audit logs for unauthorized POST requests to WordPress REST API endpoints related to form creation from accounts with subscriber-level permissions.
- Implement strict server-side input validation and restrict access to the REST API if specific plugins do not require external visibility.
Mitigations
Upgrade ACPT (Premium) plugin to a version beyond 2.0.66.
CVE-2026-105701