CVE-2026-14566
Received Received - Intake

Authentication Bypass in Advanced Customized Prompts WordPress Plugin

Vulnerability report for CVE-2026-14566, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: WPScan

Description

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata of orders belonging to other customers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
advanced_customized_prompts advanced_customized_prompts 1.0.1
woocommerce woocommerce *
advanced_customized_prompts advanced_customized_prompts to 1.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) in the Advanced Customized Prompts WordPress plugin version 1.0.1 or below. It allows any authenticated user, including low-privilege users like subscribers, to modify the custom metadata of WooCommerce orders belonging to other customers without proper checks.

Detection Guidance

Check WordPress installations for the Advanced Customized Prompts plugin version 1.0.1 or below. Look for unauthorized modifications to WooCommerce order item metadata by reviewing order logs and metadata changes. No specific commands are provided in the context.

Impact Analysis

An attacker could tamper with order metadata, potentially altering prices, product details, or customer information. This could lead to financial loss, incorrect order processing, or data integrity issues for both customers and store owners.

Compliance Impact

This vulnerability could violate GDPR by allowing unauthorized modification of personal data in orders. For HIPAA, if order metadata includes protected health information, tampering could breach compliance. Both standards require data integrity and access controls.

Mitigation Strategies

Immediately update the Advanced Customized Prompts plugin to the latest version if available. If no update exists, consider disabling the plugin until a patch is released. Restrict user roles to prevent unauthorized access to order metadata.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14566. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart