CVE-2026-105701 Overview
CVE-2026-105701 is a Remote Code Execution (RCE) vulnerability in the ACPT (Premium) plugin for WordPress. The flaw affects all versions up to and including 2.0.66. It originates from a missing capability check on the REST API form creation endpoint combined with an unsandboxed Twig environment used to render email templates. Authenticated attackers with subscriber-level access or higher can inject Twig expressions through form email_settings and execute arbitrary code on the server when a form is submitted. The weakness is classified under [CWE-434].
Critical Impact
Authenticated users with minimal privileges can achieve full remote code execution on affected WordPress servers, leading to complete site and host compromise.
Affected Products
- ACPT (Premium) plugin for WordPress — all versions through 2.0.66
- WordPress sites exposing the plugin's REST API form creation endpoint
- Any environment allowing subscriber-level or higher registrations with the plugin active
Discovery Timeline
- 2026-10-06 - CVE-2026-105701 published to the National Vulnerability Database (NVD)
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-105701
Vulnerability Analysis
The ACPT (Premium) plugin exposes a REST API endpoint that creates and configures custom forms. The handler responsible for form creation does not verify that the requester has sufficient capability to manage plugin configuration. Any authenticated user, including subscribers, can invoke the endpoint and persist arbitrary form definitions, including the email_settings fields used for notification templates.
These email templates are rendered through a Twig environment that is not sandboxed. Twig's default sandbox would restrict function calls, filters, and object access, but the plugin instantiates the engine without those protections. As a result, template expressions placed inside email_settings are evaluated with the full Twig API surface at render time, which includes constructs that can reach PHP functions. Code execution follows when a user submits the attacker-controlled form and the server renders the email body.
Root Cause
Two defects compound to produce the issue. First, broken access control on the REST route allows low-privilege accounts to create or modify forms. Second, Server-Side Template Injection (SSTI) is possible because the Twig renderer runs without the sandbox extension, treating stored administrative content as trusted input.
Attack Vector
The attacker authenticates to the WordPress site with at least subscriber privileges. They then issue a REST API request to create a form that embeds malicious Twig expressions in the email_settings property. Triggering a form submission causes the plugin to render the email template, evaluate the injected expressions, and execute arbitrary code in the context of the web server process. Full technical details are available in the Wordfence Vulnerability Report.
Detection Methods for CVE-2026-105701
Indicators of Compromise
- Unexpected POST requests from low-privilege accounts to ACPT REST API endpoints under /wp-json/ that create or update forms.
- Form definitions containing Twig control sequences such as {{, {%, or references to PHP functions inside email_settings fields.
- New or modified PHP files in wp-content/uploads/ or plugin directories following form submission activity.
- Outbound network connections from the PHP worker process to unfamiliar hosts shortly after a form submission.
Detection Strategies
- Inspect WordPress audit logs for form creation events performed by subscriber or author accounts.
- Review stored ACPT form configurations in the database for Twig syntax inside email template fields.
- Hunt web server logs for sequences where a REST form creation call is followed by a public form submission from the same session or IP.
- Correlate web process child executions (for example, php spawning sh, curl, or wget) with HTTP requests to ACPT endpoints.
Monitoring Recommendations
- Enable WordPress REST API logging and forward events to a centralized SIEM for behavioral analysis.
- Alert on new user registrations followed by REST API write operations within a short time window.
- Monitor file integrity on the wp-content/plugins/ and wp-content/uploads/ directories.
- Track outbound DNS and HTTP traffic originating from the web server for signs of post-exploitation callbacks.
How to Mitigate CVE-2026-105701
Immediate Actions Required
- Update the ACPT (Premium) plugin to a version later than 2.0.66 as published in the ACPT Change Log.
- Audit existing form definitions for Twig expressions in email_settings and remove any that are not administrator-authored.
- Review user accounts and remove subscriber or higher accounts that were created without a legitimate business reason.
- Rotate WordPress secrets, API keys, and database credentials if exploitation is suspected.
Patch Information
Refer to the ACPT Change Log for the fixed release that addresses the missing capability check and the unsandboxed Twig environment. Additional vulnerability metadata is available in the Wordfence Vulnerability Report.
Workarounds
- Disable the ACPT (Premium) plugin until the patched version can be deployed.
- Restrict user registration or require administrator approval for new accounts to limit low-privilege attacker access.
- Place a Web Application Firewall (WAF) rule in front of the ACPT REST API endpoints to block requests from non-administrator roles.
- Enforce least privilege on the PHP worker's filesystem and outbound network access to reduce post-exploitation impact.
# Configuration example: temporarily deactivate the ACPT plugin via WP-CLI
wp plugin deactivate advanced-custom-post-type
# Block anonymous and low-privilege access to ACPT REST routes at the web server layer (nginx)
location ~* /wp-json/acpt/ {
allow 10.0.0.0/8; # administrative network only
deny all;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.