CyberRota Analysis
AI-GeneratedThe Custom Post Types Plugin for WordPress versions up to 2.0.63 is vulnerable to a PHP Object Injection flaw that allows unauthenticated attackers to execute arbitrary PHP code. This critical vulnerability poses a significant risk of remote code execution, potentially compromising the integrity and availability of affected WordPress sites. WordPress administrators and developers using this plugin should prioritize immediate updates to mitigate the risk.
CVE
CVE-2026-32563
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%
WordPress
Original NVD Description
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.