CVE-2026-14563: Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover
The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated attacker can exploit the affected plugin action. No existing WordPress account or password is required.
What access can an attacker obtain?
An attacker can receive an authenticated session for any supplied email address associated with a registered user, including an administrator. They can also create arbitrary new accounts.
Are administrator accounts at risk?
Yes. Because the flaw can authenticate an attacker as any registered user by email address, administrator accounts are explicitly included.
Which plugin versions are affected?
Advanced Customized Prompts versions through 1.0.1 are affected.