CVE-2026-14563
—Unauthenticated Authentication Bypass in WordPress advanced-customized-prompts Plugin
The advanced-customized-prompts WordPress plugin through version 1.0.1 fails to verify the password before issuing an authenticated session for a supplied email address via an unauthenticated action, an improper authentication flaw (CWE-287). An unauthenticated remote attacker can trigger this by submitting any registered user's email address to the affected endpoint and receive a valid logged-in session without ever knowing the password, or can create arbitrary new accounts. This grants full control of the impersonated account, including administrator accounts, potentially leading to complete site takeover. Any WordPress site running the plugin at version 1.0.1 or earlier is affected. No public proof-of-concept or in-the-wild exploitation is currently known, and the issue is not listed in CISA KEV.
What to do: Deactivate or remove the advanced-customized-prompts plugin until a patched release newer than 1.0.1 is published, then update to the latest fixed version. Audit WordPress user accounts and authentication logs for unexpected admin sessions or newly created accounts, and rotate credentials for privileged users as a precaution.
| advanced-customized-prompts | through 1.0.1 (all versions up to and including 1.0.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.
- Ecosystems
- WordPress
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.