๐Ÿ” CVE Alert

CVE-2026-14563

CRITICAL 9.8

Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.

Vendor unknown
Product advanced-customized-prompts
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown advanced-customized-prompts

Be the first to know when new critical vulnerabilities affecting unknown advanced-customized-prompts are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / advanced-customized-prompts
0 โ‰ค 1.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7c7ad196-dff3-485f-9a50-8705bd796fb3/

Credits

0xBassia WPScan