← WordPress Vulnerabilities
WordPress security by component

advanced-customized-prompts

advanced-customized-prompts is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.

Plugin slug: advanced-customized-prompts

CVE-2026-14566: Advanced Customized Prompts lets subscribers alter order metadata

advanced-customized-prompts through 1.0.1 performs no capability, ownership, or nonce check before updating WooCommerce order-item metadata for a supplied order. Any authenticated user, including a Subscriber, can tamper with custom metadata belonging to another customer's order. The authoritative export does not identify the endpoint, action, order parameter, or metadata keys.

PublishedSep 11, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for advanced-customized-prompts
Safe version
Sep 11, 2026 CVE-2026-14566
Advanced Customized Prompts lets subscribers alter order metadata
advanced-customized-prompts through 1.0.1 performs no capability, ownership, or nonce check before updating WooCommerce order-item metadata for a supplied order. Any authenticated user, including a Subscriber, can tamper with custom metadata belonging to another customer's order. The authoritative export does not identify the endpoint, action, order parameter, or metadata keys.
See mitigation notes
CVE4.3
NVDPending
Sep 11, 2026 CVE-2026-14565
Advanced Customized Prompts permits subscriber stored XSS
advanced-customized-prompts through 1.0.1 performs no capability, ownership, or nonce check before saving popup configuration to a product and does not escape the stored values when rendering them. Any authenticated user, including a Subscriber, can store JavaScript that executes for visitors viewing the affected product. The authoritative export does not identify the endpoint, action, configuration parameters, or rendering function.
See mitigation notes
CVE5.4
NVDPending
Sep 11, 2026 CVE-2026-14563
Advanced Customized Prompts allows unauthenticated account takeover
advanced-customized-prompts through 1.0.1 does not verify a password before issuing an authenticated session for a supplied email address in an unauthenticated action. An attacker can log in as any registered user, including an Administrator, or create arbitrary new accounts. The authoritative export does not identify the action, email parameter, session function, or account-creation parameters.
See mitigation notes
CVE9.8
NVDPending