{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/acpt-premium--2.0.66/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:acpt:acpt:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-105701"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ACPT (Premium) (\u003c= 2.0.66)"],"_cs_severities":["high"],"_cs_tags":["wordpress","rce","web-application","cve-2026-105701"],"_cs_type":"advisory","_cs_vendors":["ACPT"],"content_html":"\u003cp\u003eThe ACPT (Premium) plugin for WordPress contains a critical vulnerability (CVE-2026-105701) that allows authenticated attackers with subscriber-level access or higher to execute arbitrary code on the underlying server. The flaw exists due to a missing capability check on the REST API endpoint responsible for form creation. This endpoint fails to properly validate the user's permissions, allowing the injection of malicious payloads within the email_settings parameter. Because the plugin utilizes an unsandboxed Twig template rendering environment for these email templates, an attacker can craft specifically formatted Twig expressions that are executed server-side. This vulnerability affects all versions of the ACPT (Premium) plugin up to and including 2.0.66. Successful exploitation requires an attacker to first create a malicious form object via the REST API and then trigger the form submission process, which forces the rendering engine to process the injected code.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full Remote Code Execution (RCE) on the WordPress server. As WordPress typically runs with the permissions of the web server user (such as www-data), an attacker can read sensitive files, modify site content, pivot to the internal network, or deploy persistent backdoors. Given the ubiquity of WordPress installations, this vulnerability poses a high risk for sites utilizing the ACPT Premium plugin for form management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the ACPT (Premium) plugin to a version released after 2.0.66 immediately to receive the security patch.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized POST requests to WordPress REST API endpoints related to form creation from accounts with subscriber-level permissions.\u003c/li\u003e\n\u003cli\u003eImplement strict server-side input validation and restrict access to the REST API if specific plugins do not require external visibility.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T08:53:57Z","date_published":"2026-10-06T08:53:57Z","id":"https://feed.craftedsignal.io/briefs/2026-10-acpt-rce/","summary":"Authenticated attackers with subscriber-level access can achieve remote code execution in ACPT (Premium) versions up to 2.0.66 by injecting malicious Twig expressions via the REST API.","title":"Remote Code Execution in ACPT (Premium) WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-acpt-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - ACPT (Premium) (\u003c= 2.0.66)","version":"https://jsonfeed.org/version/1.1"}