plugin

Ace Post Type Builder Vulnerabilities

1 known security issue reported for the Ace Post Type Builder WordPress plugin. Most recent disclosed Nov 24, 2025.

1 medium

Running Ace Post Type Builder on your site? Check whether your installed version is affected.

Scan your site free

Ace Post Type Builder <= 1.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Custom Taxonomy Deletion via 'taxonomy' Parameter

medium

The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing authorization validation on the cptb_delete_custom_taxonomy() function in all versions up to, and including, 1.9. This makes it possible for authenticated attackers, with Subscriber-level access and abov...

CVSS:
5.3
Affected:
up to 1.9
Fixed in:
2.0
Disclosed:
Nov 24, 2025

CVE-2025-13405 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database