WordPress security by component
advanced-customized-prompts
advanced-customized-prompts is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
advanced-customized-promptsLatest vulnerability
CVE-2026-14566: Advanced Customized Prompts lets subscribers alter order metadata
advanced-customized-prompts through 1.0.1 performs no capability, ownership, or nonce check before updating WooCommerce order-item metadata for a supplied order. Any authenticated user, including a Subscriber, can tamper with custom metadata belonging to another customer's order. The authoritative export does not identify the endpoint, action, order parameter, or metadata keys.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-14566
Advanced Customized Prompts lets subscribers alter order metadata
advanced-customized-prompts through 1.0.1 performs no capability, ownership, or nonce check before updating WooCommerce order-item metadata for a supplied order. Any authenticated user, including a Subscriber, can tamper with custom metadata belonging to another customer's order. The authoritative export does not identify the endpoint, action, order parameter, or metadata keys.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 11, 2026 |
CVE-2026-14565
Advanced Customized Prompts permits subscriber stored XSS
advanced-customized-prompts through 1.0.1 performs no capability, ownership, or nonce check before saving popup configuration to a product and does not escape the stored values when rendering them. Any authenticated user, including a Subscriber, can store JavaScript that executes for visitors viewing the affected product. The authoritative export does not identify the endpoint, action, configuration parameters, or rendering function.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Sep 11, 2026 |
CVE-2026-14563
Advanced Customized Prompts allows unauthenticated account takeover
advanced-customized-prompts through 1.0.1 does not verify a password before issuing an authenticated session for a supplied email address in an unauthenticated action. An attacker can log in as any registered user, including an Administrator, or create arbitrary new accounts. The authoritative export does not identify the action, email parameter, session function, or account-creation parameters.
|
See mitigation notes |
CVE9.8
NVDPending
|