ZeroHour

CVE-2026-14563

Unauthenticated Authentication Bypass in WordPress advanced-customized-prompts Plugin

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

The advanced-customized-prompts WordPress plugin through version 1.0.1 fails to verify the password before issuing an authenticated session for a supplied email address via an unauthenticated action, an improper authentication flaw (CWE-287). An unauthenticated remote attacker can trigger this by submitting any registered user's email address to the affected endpoint and receive a valid logged-in session without ever knowing the password, or can create arbitrary new accounts. This grants full control of the impersonated account, including administrator accounts, potentially leading to complete site takeover. Any WordPress site running the plugin at version 1.0.1 or earlier is affected. No public proof-of-concept or in-the-wild exploitation is currently known, and the issue is not listed in CISA KEV.

What to do: Deactivate or remove the advanced-customized-prompts plugin until a patched release newer than 1.0.1 is published, then update to the latest fixed version. Audit WordPress user accounts and authentication logs for unexpected admin sessions or newly created accounts, and rotate credentials for privileged users as a precaution.

Affected
advanced-customized-promptsthrough 1.0.1 (all versions up to and including 1.0.1)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.

Ecosystems
WordPress
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.