CVE-2026-14563 Details
Description
The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.
A vulnerability in the Advanced Customized Prompts WordPress plugin, affecting versions through 1.0.1, allows unauthenticated attackers to bypass authentication and log in as any registered user, including administrators. The vulnerability arises because the plugin does not verify passwords before granting authenticated sessions based on supplied email addresses during unauthenticated actions. This flaw also enables the creation of arbitrary new accounts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/7c7ad196-dff3-485f-9a50-8705bd796fb3/ | [email protected] | AdvisoryExploitPartial ContentRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| advanced-customized-prompts | <= 1.0.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 11, 2026 | New CVE Received | [email protected] |
Volerion