{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/acpt--2.0.66/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:acpt:acpt:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-15354"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ACPT (\u003c= 2.0.66)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin-vulnerability","privilege-escalation","web-application"],"_cs_type":"advisory","_cs_vendors":["ACPT"],"content_html":"\u003cp\u003eThe ACPT (Premium) plugin for WordPress is vulnerable to a critical privilege escalation vulnerability, assigned CVE-2026-15354, affecting all versions up to and including 2.0.66. The flaw exists within the plugin's \u003ccode\u003esubmit()\u003c/code\u003e function, which fails to verify user authorization before executing account update operations. By interacting with a public-facing ACPT form, an unauthenticated attacker can manipulate the target user ID parameter passed to the \u003ccode\u003ewp_update_user()\u003c/code\u003e function. This allows the attacker to arbitrarily modify the email address and password of any registered user on the WordPress site. If the target is an administrator, this results in a full site takeover. Organizations using this plugin should immediately update to a patched version once available or disable public-facing forms managed by the plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site utilizing the ACPT Premium plugin with a public-facing user form enabled.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the public form to capture the request structure intended for the \u003ccode\u003esubmit()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the \u003ccode\u003esubmit()\u003c/code\u003e function endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects a target user ID (e.g., ID 1 for the default administrator) into the request parameters.\u003c/li\u003e\n\u003cli\u003eAttacker includes a new, controlled email address and password within the request body.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to validate the request sender's authorization status.\u003c/li\u003e\n\u003cli\u003eThe plugin executes \u003ccode\u003ewp_update_user()\u003c/code\u003e using the attacker-supplied parameters.\u003c/li\u003e\n\u003cli\u003eAttacker gains unauthorized administrative access to the WordPress site using the updated credentials.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform a full site takeover by hijacking administrative accounts. This leads to the potential for data exfiltration, total site defacement, and the deployment of additional backdoors or malware within the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit WordPress instances for public-facing forms generated by the ACPT plugin and disable them until the plugin is patched.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests targeting common plugin submission endpoints if available in documentation.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided security update for ACPT Premium as soon as it is released.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T07:24:32Z","date_published":"2026-09-04T07:24:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-acpt-privesc/","summary":"The ACPT Premium WordPress plugin contains a critical authorization flaw in the submit() function, allowing unauthenticated attackers to hijack administrative accounts by overwriting credentials.","title":"Unauthenticated Privilege Escalation in ACPT Premium Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-acpt-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - ACPT (\u003c= 2.0.66)","version":"https://jsonfeed.org/version/1.1"}