Ace Post Type Builder <= 1.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Custom Taxonomy Deletion via 'taxonomy' Parameter

2025-11-24 19:07
Legion Hunter

Strategic Overview

Status
Patched in 2.0
Affected PluginAce Post Type Builder
Affected Version<= 1.9
CVSS5.3Medium
CVECVE-2025-13405
View all Ace Post Type Builder vulnerabilities

Vulnerability Overview

The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing authorization validation on the cptb_delete_custom_taxonomy() function in all versions up to, and including, 1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary custom taxonomies.

Technical Analysis

REMEDIATION: Update to version 2.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C