WPHizmet

Eklenti güvenlik geçmişi

ACPT (Premium) güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) ACPT (Premium) eklentisi için 2 açık kaydı bulunuyor; en yenisi 6 Ekim 2026 tarihli. Bunların 2 tanesi kritik veya yüksek önemde, 1 tanesi oturum açmadan istismar edilebiliyor.

Toplam kayıt
2
Kritik veya yüksek
2
Oturumsuz istismar
1
Son kayıt
6 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-105701Yüksek · 8,86 Ekim 2026

    uzaktan kod çalıştırma

    Etkilenen sürümler: 2.0.66 ve öncesi

    The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. The exploit requires the attacker to first create a form with malicious email_settings via the REST API endpoint, then trigger form submission to execute the injected Twig expressions.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-15354Kritik · 9,84 Eylül 2026

    yetki yükseltme

    Etkilenen sürümler: 2.0.66 ve öncesi · Oturum açmadan istismar edilebilir

    The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.